苹果已修补 CoreGraphics 中的一个零日漏洞。此前,苹果警告称,攻击者可能已利用该漏洞入侵少量经过精心挑选的目标。该漏洞编号为 CVE-2026-86950,是 CoreGraphics 中的一处越界写入漏洞;CoreGraphics 是苹果用于在其各操作系统中处理图形的框架。苹果的安全公告称,处理恶意构造的文件可能使攻击者在易受攻击的设备上执行任意代码。
Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device.
这家以水果为名的厂商表示,已通过改进边界检查来解决问题,但该漏洞似乎在苹果来得及修复之前就已流入真实环境。公司称:“苹果获悉,有报告称,该问题可能已被用于一场极其复杂的攻击,受害目标是 iOS 27 之前特定 iOS 版本上的个别特定人员。”库比蒂诺在遇到这种显然已被他人派上用场的安全漏洞时,一如既往地没有透露太多细节。
The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the wild before Apple could squash it. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said. As is customary when Cupertino encounters the sort of security bug somebody has apparently found useful, further details are thin on the ground.
苹果没有说明攻击目标是谁、有多少人受到影响、攻击者是谁,也没有具体说明该漏洞是如何被利用的。不过,其措辞表明,这并非一个在整个互联网上遭到无差别利用的漏洞,因此不排除它被作为某次定向间谍软件攻击的一部分。Meta 产品安全团队向苹果报告了 CVE-2026-86950,但苹果的安全公告和 Meta 均未进一步披露该漏洞是如何发现的,以及据称利用该漏洞实施了哪些攻击。
Apple didn't say who was targeted, how many people were affected, who was behind the attacks, or exactly how the vulnerability was being exploited. However, its choice of words suggests this wasn't a bug being exploited indiscriminately across the internet, and raises the possibility that it was used as part of a targeted spyware campaign. Meta Product Security reported CVE-2026-86950 to Apple, but neither Apple's advisory nor Meta has provided further technical details on how the flaw was discovered or the attacks in which it was allegedly used.
修复已于周一随 iOS 26.7.1 和 iPadOS 26.7.1 发布。苹果列出的可获得此次更新的受影响设备包括 iPhone 11 及后续机型、12.9 英寸 iPad Pro(第三代及后续机型)、11 英寸 iPad Pro(第一代及后续机型)、iPad Air(第三代及后续机型)、iPad(第八代及后续机型)以及 iPad mini(第五代及后续机型)。
The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1. Apple lists affected devices receiving the update as the iPhone 11 and later, iPad Pro 12.9-inch (third generation and later), iPad Pro 11-inch (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later).
苹果明确表示,这些攻击波及运行 iOS 27 之前各版本系统的设备,但尚未说明具体针对哪些旧版系统。这一漏洞又为苹果不断增多的一类漏洞清单添了一项——这些漏洞都是在用户尚无补丁可用时便遭到利用。CVE-2026-86950 是苹果今年修复的第七个零日漏洞。对于仍在使用受影响版本的人,安全建议依旧平淡无奇:安装更新,别等着亲眼看看所谓“极其复杂的攻击”究竟是什么样子。®
Apple specifically says the attacks hit devices running versions of iOS before iOS 27, though it hasn't said exactly which older releases were targeted. The flaw adds another entry to Apple's growing collection of vulnerabilities caught being abused before users had a patch, with CVE-2026-86950 landing as the seventh zero-day fixed by the company this year. For anyone still running the affected releases, that leaves the usual less-than-thrilling security advice: install the update rather than waiting to find out exactly what an "extremely sophisticated attack" looks like. ®