Apple Patches an Exploited CoreGraphics Flaw in Older macOS Releases
macOS Sequoia 15.8.1 and Tahoe 26.7.1 address CVE-2026-86950, a CoreGraphics flaw linked to targeted, sophisticated attacks.
Apple has patched a CoreGraphics vulnerability that may already have been used in highly targeted attacks. The issue, tracked as CVE-2026-86950, is addressed in macOS Sequoia 15.8.1 and the corresponding current security release for macOS Tahoe.
Apple says a maliciously crafted file could trigger an out-of-bounds write and lead to arbitrary code execution. In practical terms, processing the wrong file could allow attacker-controlled code to run on the affected device.
Why this update deserves priority
This is not only a theoretical weakness disclosed before exploitation. Apple says it is aware of a report that the issue may have been used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. That wording suggests a narrow campaign rather than indiscriminate mass exploitation, but a publicly available patch still deserves prompt installation.
Meta Product Security reported the flaw. Apple says the underlying memory-safety problem was corrected with improved bounds checking.
How to update a Mac
Open System Settings, choose General and then Software Update. Install the newest release offered for the version of macOS supported by the Mac. Save active work and make a current backup before starting, because the installation requires a restart.
After the restart, return to Software Update or open About This Mac to confirm the version. Sequoia users should see 15.8.1. Tahoe users should be on 26.7.1, while machines eligible for the newer Golden Gate line may receive a different current release.
Avoid unofficial update links
Security-update urgency is frequently abused in phishing messages. Start the update from macOS settings or Apple’s official support pages, not from a download link delivered by email or a pop-up. Organizations that delay updates for compatibility testing should review the CoreGraphics exposure and prioritize high-risk users who routinely receive untrusted documents or media.
Official source
Read the official product or support information.
Some links on this page may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.