Apple patches a CoreGraphics zero-day exploited against targeted individuals
An out-of-bounds write in CoreGraphics allows code execution when a crafted file is opened, and CISA added it to the KEV catalog after confirmed exploitation. Roll out iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1 or macOS Tahoe 26.7.1 immediately, starting with the devices of exposed people.