Apple Patches CoreGraphics Zero-Day Flaw Targeted In Attacks

Apple to Release iOS 18 Security Update to Fix DarkSword Exploit on More iPhones
Image: Apple

Apple has rolled out critical security updates to address a zero-day vulnerability that hackers successfully exploited in highly targeted, sophisticated attacks. The flaw affects the CoreGraphics framework, which handles two-dimensional vector graphics, image rendering, and text drawing across the company’s operating systems. This marks the second zero-day vulnerability the tech giant has patched this year, following a similar security fix released back in February.

The security patch fixes an out-of-bounds write vulnerability

The security issue, officially tracked as CVE-2026-20700, involves an out-of-bounds write vulnerability. Meta Product Security originally discovered the flaw and reported it. If a user opens a maliciously crafted file, the vulnerability allows attackers to run arbitrary code on the device. To resolve the issue, the update improves bounds checking within the software framework.

The patches are now available across a wide range of devices. Users can download iOS 26.7.1 and iPadOS 26.7.1 to protect their mobile hardware. For desktop users, the fix is included in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. These updates secure numerous iPad, iPhone, and Mac models against potential intrusions.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

The company urges users to install these vital patches promptly

While hackers likely used this exploit in highly specific and targeted campaigns, security experts strongly recommend that all users update their devices immediately. Leaving hardware unpatched keeps it open to ongoing or future attacks. Installing the update is the best way to ensure personal data remains safe from this specific threat.

This recent patch follows a pattern of necessary security maintenance. Earlier this year, the company resolved a high-severity flaw in Beats Studio Buds that allowed attackers to listen in on conversations. It also addressed several vulnerabilities in older devices that were targeted by the Coruna exploit kit for cyberespionage and cryptocurrency theft. As users prepare for future major releases like iOS 27, keeping current systems up to date provides the strongest defense against evolving digital threats.

Discussion

Join the discussionCommenting as a guest — your email is never published · Log in

Protected by Akismet — be kind, stay on topic.

This site uses Akismet to reduce spam. Learn how your comment data is processed.