Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks
Apple has released security updates for macOS Tahoe and macOS Sequoia to address a vulnerability that could allow arbitrary code execution.
The updates, published on September 28, 2026, fix an issue in the CoreGraphics image processing framework tracked as CVE-2026-86950. The vulnerability is an out-of-bounds write condition that may be triggered when the system processes a maliciously crafted file.
According to Apple, the same flaw may have been exploited in highly targeted attacks against iOS devices running versions prior to iOS 27. The company did not disclose further details about the reported attacks.
The CVSS v3.1 base score assigned by CISA is 8.8, placing the issue in the High severity category. Apple has addressed the vulnerability in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. The company also released macOS Golden Gate 27.0.1 on the same day, although specific CVE details for that update were not disclosed.
Related articles
Apple Releases iOS 26.7.1 and iPadOS 26.7.1 to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted Attacks
Apple has issued iOS 26.7.1 and iPadOS 26.7.1 to address a high-severity vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when processing a specially crafted file due to an out-of-bounds write. The company stated that the issue may have been exploited in sophisticated, targeted attacks against specific individuals on versions prior to iOS 27. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. On the same day, Apple also released iOS 27.0.1 and iPadOS 27.0.1, though those updates did not reference CVE-2026-86950. The patches close a vector that could be abused for remote code execution in image rendering components.
Fundamental Flaw in File Monitoring APIs Exposes Keystrokes and App Activity Across Windows, Linux, Android, and macOS
Researchers from Graz University of Technology demonstrated how built-in file change notification mechanisms can leak sensitive user activity without requiring elevated privileges. The affected subsystems include inotify on Linux, FileObserver on Android, ReadDirectoryChangesW on Windows, and FSEvents on macOS. On Linux the technique enables reconstruction of typed text with 93-100% accuracy by monitoring /dev/input/event4 timestamps. Android apps can break sandbox isolation to observe messaging events, while Windows monitoring of browser cache files reveals visited websites at 97.8% accuracy. Only partial mitigations have been deployed in Linux and Windows, with no fixes available for Android or macOS. Additional attacks remain possible, including detection of password prompts to facilitate phishing overlays.
16-Year-Old Researcher Discovers Authentication Bypass in Microsoft Titan Analytics Platform
A 16-year-old security researcher using the pseudonym Faav identified a critical flaw in Microsoft Titan, the company's internal analytics platform. The vulnerability allowed an attacker to submit forged JSON Web Tokens that bypassed signature verification and granted administrator privileges. With these rights, the researcher could execute arbitrary SQL queries against connected databases containing metadata from nearly 10,000 tables. Microsoft received the report on September 5, disabled public API access four days later, and issued a $5,000 bounty on September 17. No evidence has emerged that the issue was exploited by malicious actors before remediation. The researcher accessed only limited metadata and a small number of records during testing and did not exfiltrate customer personal data.
Quantum Randomness Failures Allow AI to Extract Predictable Patterns from QRNG Devices
Quantum physics can generate true randomness, yet engineering flaws in QRNG implementations often introduce predictable noise that attackers can exploit. The European Telecommunications Standards Institute has published ETSI TR 104 171, a technical report guiding the design and evaluation of quantum random number generators used in cryptographic key creation. The report highlights that sensors, power supplies, signal processors, and post-processing algorithms can leak patterns even when statistical tests pass. Artificial intelligence systems are now capable of analyzing large datasets to detect these subtle correlations. Side-channel emissions such as power consumption and electromagnetic radiation further increase the risk by linking physical signals to output values. ETSI recommends adopting an entropy zero trust model that includes continuous monitoring, hardware protection, encrypted delivery channels, and detailed logging of generation events. In multi-tenant environments, client streams must remain isolated to prevent cross-contamination of entropy sources.