Full Report
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
Analysis Summary
# Vulnerability: Apple CoreGraphics Out-of-Bounds Write Zero-Day
## CVE Details
- **CVE ID:** CVE-2026-20700
- **CVSS Score:** N/A (High/Critical severity implied by RCE capability)
- **CWE:** CWE-787: Out-of-bounds Write
## Affected Systems
- **Products:** iOS, iPadOS, macOS (Sequoia and Tahoe).
- **Versions:**
- iOS versions prior to 26.7.1 (specifically targeted on versions before iOS 27).
- macOS Sequoia prior to 15.8.1.
- macOS Tahoe prior to 26.7.1.
- **Configurations:** Systems processing maliciously crafted image or graphic files via the CoreGraphics framework.
- **Specific Hardware:**
- iPhone 11 and later.
- iPad Pro (12.9-inch 3rd gen+, 11-inch 1st gen+).
- iPad Air (3rd gen+), iPad (8th gen+), and iPad mini (5th gen+).
## Vulnerability Description
The flaw exists within **CoreGraphics**, a fundamental framework used for rendering 2D vector graphics and images across Apple platforms. The vulnerability is an **out-of-bounds write**, occurring when the software writes data past the end of the intended memory buffer. This memory corruption can be triggered by processing a maliciously crafted file, leading to a program crash, data corruption, or **Arbitrary Code Execution (ACE)**.
## Exploitation
- **Status:** Exploited in the wild (Zero-day). Reports indicate "extremely sophisticated" targeted attacks against specific individuals.
- **Complexity:** Medium to High (requires crafting specific malicious graphic files).
- **Attack Vector:** Network (Remote via malicious file delivery).
## Impact
- **Confidentiality:** High (Potential for full system compromise and data theft).
- **Integrity:** High (Ability to modify data or execute unauthorized code).
- **Availability:** High (Can lead to system/application crashes).
## Remediation
### Patches
Apple has addressed this issue in the following updates through improved bounds checking:
- **iOS 26.7.1**
- **iPadOS 26.7.1**
- **macOS Tahoe 26.7.1**
- **macOS Sequoia 15.8.1**
### Workarounds
- No specific software workarounds are provided. Users are urged to apply the security updates immediately.
- General hardening: Avoid opening unsolicited or suspicious image files or documents from unknown sources.
## Detection
- **Indicators of Compromise:** Unusual application crashes when rendering images or PDF documents; presence of unauthorized processes.
- **Detection methods and tools:** System administrators should monitor for devices running outdated firmware. Security teams should look for anomalous crashes in the CoreGraphics process.
## References
- Apple Security Advisory (iOS/iPadOS): [https://support.apple.com/en-us/149226]
- Apple Security Advisory (macOS Tahoe): [https://support.apple.com/en-us/149228]
- Apple Security Advisory (macOS Sequoia): [https://support.apple.com/en-us/149229]
- CWE-787 Definition: [https://cwe.mitre.org/data/definitions/787.html]