Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Tesla sustains its EV sales momentum despite US troubles

    October 2, 2026

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    Bitcoin survived 5% yields but crypto’s cheap-money era did not

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Tesla sustains its EV sales momentum despite US troubles
    • macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
    • Bitcoin survived 5% yields but crypto’s cheap-money era did not
    • Petrobras strikes another oil-bearing zone in Equatorial Margin frontier
    • Two Wisconsin sheriff races test the future of local ICE cooperation
    • It’s true: this is my final column. You have exactly 24 hours to complain before my inbox self-destructs | Marina Hyde
    • Are Texas Muslims ordering businesses to remove haram products within 30 days? Here’s the truth
    • Ukraine calls for tighter sanctions as Russian attacks spark Kyiv gridlock | Russia-Ukraine war News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 1, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Apple released new versions of iOS and macOS to address a zero-day vulnerability that a threat actor is actively exploiting in targeted attacks.

    The out-of-bounds write vulnerability, tracked as CVE-2026-86950, affects Apple’s CoreGraphics framework, which macOS and iOS use to render and manipulate 2D graphics. The vulnerability affects a broad range of Apple devices, including iPhones dating back to the iPhone 11 and multiple generations of iPads.

    Extremely Sophisticated Attacks

    The flaw has a CVSS score of 8.8 and can allow an attacker to execute arbitrary code on an affected system. According to Apple’s advisory, the vulnerability is being exploited “in an extremely sophisticated attack against specific targeted individuals” on versions of iOS before iOS 27. The technology giant said it has addressed the vulnerability by adding checks to ensure the software does not write data beyond the memory allocated for it.

    Related:Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

    The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog — a source that it wants organizations to use to prioritize patching efforts. In keeping with its binding operative directive (BOD 26-04) from earlier this year for high-priority vulnerabilities, CISA has given federal civilian executive branch agencies three days to apply Apple’s recommended mitigation for the vulnerability. As per BOD 26-04, these agencies must also conduct a forensic triage by Oct. 2 to determine if they have already been compromised via CVE-2026-86950.

    Apple credited Meta with disclosing the vulnerability to the company but has not released any information on the exploit activity or who it might be targeting.

    Adam Bynton, enterprise security manager at Jamf, says CVE-2026-86950 is significant because it affects a component of the graphics stack used to process content across Apple’s operating systems. Though Apple has only referenced the attacks as targeting iOS, the company has patched the same flaw in macOS Tahoe and Sequoia, Boynton points out.

    “The broader pattern is worth watching,” he says. “We continue to see highly sophisticated attacks look for routes through components that process untrusted content.” As an example, he pointed to CVE-2025-55177, a vulnerability in WhatsApp that attackers exploited in combination with CVE-2025-43300, another out-of-bounds zero-day vulnerability, this time in Apple’s ImageIQ technology.

    “We have also seen Apple disclose targeted exploitation involving WebKit and other memory-safety vulnerabilities,” Boynton says.

    Related:South Africa Seeks Help After Cyberattack Targets Air Traffic Control

    That shouldn’t be interpreted as Apple devices being broadly insecure, he says. “Apple describes these attacks as highly sophisticated and targeted at a very small population, which is why separating targeted exploitation from everyday enterprise risk is important.”

    Is a Nation-State Actor Behind the Attacks?

    It’s unclear who is exploiting CVE-2026-86950 and if the attacks are ongoing. But Apple’s description of the attacks as being extremely sophisticated hints that a nation-state actor or spyware firm might be involved. WhatsApp, for instance, has previously accused Israel’s NSO Group of using its servers to distribute its Pegasus spyware on mobile devices belonging to targeted individuals.

    Ensar Seker, chief information security officer at SOCRadar, says a memory-corruption vulnerability like CVE-2026-86950, which can lead to arbitrary code execution during file processing, creates the potential for a low-interaction or potentially zero-click attack chain when combined with an appropriate delivery mechanism.

    The other important detail is Apple’s description of the exploitation as an “extremely sophisticated attack” against specific individuals, he says. “That language generally points toward highly targeted operations rather than broad cybercrime,” he adds. “Organizations should therefore treat this less like a theoretical vulnerability and more like an indication that advanced threat actors continue to invest heavily in finding ways around Apple’s security architecture.”

    Related:AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

    The trend is not simply that Apple has more vulnerabilities, Seker continues. What stands out is the continued discovery of flaws being used in sophisticated exploit chains targeting devices that many organizations have traditionally viewed as lower-risk endpoints.

    “Over the past year, we have seen exploited vulnerabilities involving WebKit, media and image processing, privilege escalation, authorization controls, and memory corruption,” Seker says. “Attackers are increasingly looking for chains rather than a single vulnerability: One flaw provides initial code execution, another escapes a sandbox or increases privileges, and additional components establish access to sensitive information.”

    The fact that Apple devices are strategically important endpoints at many enterprises, and many high-value targets frequently use iPhones and Macs, also makes the economics of developing exploits targeting Apple vulnerabilities more attractive. The first priority for organizations therefore is to reduce patch latency for Apple products. “When Apple identifies active exploitation, security teams should treat the update as an emergency security patch rather than waiting for the normal monthly patching cycle,” Seker says.Organizations should also bring Apple devices fully into their enterprise security program and stop treating them as inherently secure endpoints simply because of Apple’s security architecture. “Enterprises need centralized device management, enforced OS minimum versions, rapid update policies, visibility into device compliance, and controls that prevent outdated devices from accessing sensitive corporate resources,” he says.

    Apple attacks targeted Vulnerability weaponized ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    Ukraine calls for tighter sanctions as Russian attacks spark Kyiv gridlock | Russia-Ukraine war News

    OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

    Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Rolling the cyber dice with open-source and open-weight AI models

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Tesla sustains its EV sales momentum despite US troubles

    October 2, 2026

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    Bitcoin survived 5% yields but crypto’s cheap-money era did not

    October 2, 2026

    Petrobras strikes another oil-bearing zone in Equatorial Margin frontier

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Tesla sustains its EV sales momentum despite US troubles

    October 2, 2026

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    October 2, 2026

    Bitcoin survived 5% yields but crypto’s cheap-money era did not

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.