Apple released security updates for a zero-day vulnerability in CoreGraphics that the company says may have been exploited in a highly sophisticated attack against specific individuals using older versions of iOS.
Tracked as CVE-2026-20700, the flaw is an out-of-bounds write issue. Apple says processing a maliciously crafted file could allow arbitrary code execution. Meta Product Security discovered the vulnerability.
CoreGraphics handles vector graphics, image rendering and text drawing across Apple operating systems. Apple addressed the flaw with improved bounds checking in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
The source report says this is the second zero-day Apple has fixed after exploitation in the wild since the start of the year. It identifies the other flaw as a dyld code-execution vulnerability, but gives it the same identifier, CVE-2026-20700, and says it was patched in February. That identifier is inconsistent with the CoreGraphics vulnerability details in the report.
Comments
0No comments yet. Be the first to comment.