Contents

Apple CoreGraphics Zero Day Let One Crafted File Run Code on iPhones and Macs

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 
Contents

Your iPhone 11 or newer had a hole that let one crafted file run code. Attackers already used it on chosen people. It sat in the code that draws what your apps show, and Apple hasn’t said how the file got in.

Apple wrote a sentence this week that it had written only once before this year in its iPhone updates. The flaw “may have been exploited in an extremely sophisticated attack against specific targeted individuals.” An attacker had something that worked and aimed it at people they picked while the hole was still open. The first time this year was in February, for a bug in the code that goes to work each time an app starts, the dynamic linker called dyld.

This time the hole was in CoreGraphics, a part of iOS and macOS you never see by name. When an app on your iPhone or your Mac shows a picture or a PDF, it hands the drawing to shared code inside the system, and for two-dimensional drawing that code is CoreGraphics. Apple’s own developer pages say it also makes, shows and reads PDF files. It runs underneath the apps you open, and you cannot switch it off.

The bug is what Apple calls an out-of-bounds write. A program sets aside a block of memory for a job, for instance the contents of a file it has to draw. Because of the bug, it then writes outside that block, into memory that belongs to something else. If the file is built so that the attacker decides what lands there, the attacker can change what the program does next. That is how “processing a maliciously crafted file” turns into “arbitrary code execution” in Apple’s notes: the attacker’s own code, running on your phone.

Apple did not say what kind of file it was, how it reached the phone, whether the owner had to tap anything, who was behind it or how many people were hit. Meta’s security team gets the credit in Apple’s notes, and its researchers have reported other bugs in how Apple handles files this year too, among them one in ImageIO, the part of iOS that reads image files, where “processing an image may lead to arbitrary code execution.” Neither company has shared details about this one.

In 2021 the spyware researchers at Citizen Lab examined the iPhone of a Saudi activist and found files that ended in .gif but were something else. Four of them were PDF files, sent through iMessage. The lab linked the attack to Pegasus, the spyware of NSO Group, and named it FORCEDENTRY.

Google’s bug-hunting team, Project Zero, later took the attack apart and showed what happened when such a message came in. iMessage handed any file ending in .gif to a helper process “after a message has been received but well before the message is shown.” The phone was already preparing the picture for the chat before its owner knew there was a message. That helper did not go by the file name either. The image code worked out the format from the contents, which meant, in the team’s words, that “over 20 image codecs are suddenly part of the iMessage zero-click attack surface.” To target someone, the attackers needed only a phone number or an Apple ID.

The flaw those fake GIFs hit was in CoreGraphics, the same part of iOS as this week’s bug. A number in its PDF code could grow too large and wrap around, which is called an integer overflow. From there the attackers built a small working computer inside the image data, out of more than 70,000 simple logic commands, and it ran inside the image decoder while the phone unpacked the picture. The team called it “one of the most technically sophisticated exploits we’ve ever seen.” Apple closed it on September 13, 2021.

Two years later it happened again. In September 2023 the same lab found an attack on the iPhone of someone working for a civil society organization in Washington DC. This time the way in was attachments of the kind Apple Wallet uses for boarding passes and tickets, called PassKit, with malicious images inside. They came from an attacker’s iMessage account, and again the owner did not have to do anything. The attack delivered the same spyware, and the researchers called it BLASTPASS. They also wrote that they believed “Lockdown Mode blocks this particular attack,” and that Apple’s security engineers confirmed it to them.

In August 2025 it was images once more, this time through WhatsApp, the messaging app of the company that found this week’s bug. The app had a flaw in how it kept linked devices in sync. A person with no link to you could make your phone fetch a file from an address of their choosing and process it. In the company’s words, the flaw “could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.”

The company wrote that it may have been used together with a flaw in Apple’s image-reading code, which Apple described as “Processing a malicious image file may result in memory corruption.” The first hole brought the file onto the phone, and the second turned the file into code. The pair may have been used, according to the company, in “a sophisticated attack against specific targeted users.”

Nothing public ties that attack to this one. In 2021, 2023 and 2025, the way into a targeted iPhone ran through a file the phone processed without its owner choosing to open it, and this week’s hole sits in the code that draws files.

An attack chain this strong still only lands on a few people. Apple sends threat notifications to people it believes were targeted. On its page about those warnings it gives part of the reason: “Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent.”

A chain like that takes a lot of work to build, and once somebody examines a phone it was used on, as happened in 2021 and 2023, the hole gets found and closed. That keeps a fresh chain aimed at a few people, the ones someone wants to watch very badly, and Apple names them: “journalists, activists, politicians, and diplomats.” People in more than 150 countries have received its warning since 2021. Apple also writes that “the vast majority of users will never be targeted by such attacks.”

These attacks are still happening. On September 2 the same lab reported that a member of Serbia’s student protest movement had been infected with the same spyware through an iMessage zero-click exploit, between December 2025 and January 2026. The lab examined the phone after the student received Apple’s warning. The SHARE Foundation in Serbia, which worked with the lab on the case, counted at least 14 people from the movement and civil society, plus an opposition member of parliament, who recently received the same warning.

Once a chain is out, it does not stay with its first owner. The dyld bug Apple fixed in February is the example. Google’s threat intelligence team found it inside DarkSword, an exploit chain for iOS 18.4 to 18.7, and at least three different groups used it. One went after users in Saudi Arabia through a fake Snapchat site, and a Turkish company that sells surveillance tools used it in Turkey and Malaysia. A suspected Russian espionage group planted it on hacked Ukrainian websites. The team wrote that this spread “across disparate threat actors mirrors the previously discovered Coruna iOS exploit kit.” The longer an iPhone goes without updates, the longer it stays open to whoever gets hold of a chain next.

On September 29 CISA, the US cybersecurity agency, added this week’s flaw to its list of bugs known to be used in attacks. It only puts a bug on that list when there is “reliable evidence that the vulnerability has been actively exploited in the wild.” Federal agencies got until October 2 to deal with it, which is three days. The agency’s alert also tells them to check whether an attacker got into a system before the patch went in.

On September 28 Apple shipped the fix in iOS 26.7.1 and iPadOS 26.7.1, and for Macs in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple says the attacks it knows of ran on versions of iOS before iOS 27. It put out no update for iPhones still on iOS 18 or for Macs on macOS Sonoma, although both got security updates in August, and it does not say whether they are affected.

For iPhones that leaves two paths, because the iPhone 11 and later can run both iOS 26 and iOS 27. Five iPads have only one. These models are on Apple’s list for iPadOS 26.7.1 and missing from the list for iPadOS 27:

  • โ†’ iPad Pro 12.9-inch (3rd generation)
  • โ†’ iPad Pro 11-inch (1st generation)
  • โ†’ iPad Air (3rd generation)
  • โ†’ iPad (8th generation)
  • โ†’ iPad mini (5th generation)

For those five, 26.7.1 is the only way to close this hole.

What to do today:

  • โ†’ iPhone or iPad on iOS 26: Settings, General, Software Update, and install 26.7.1. On iOS 27, Apple lists no fix for this flaw, and the attacks it knows of ran on older versions.
  • โ†’ Mac: install macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, depending on the version you run.
  • โ†’ If your work makes you a likely target, as a journalist, activist, politician or diplomat, turn on Lockdown Mode: Settings, Privacy & Security, Lockdown Mode, Turn On Lockdown Mode, then Turn On & Restart and enter your passcode. It blocks most attachment types in Messages apart from certain images, video and audio, and makes links and link previews unavailable. That is the setting that stopped the 2023 attack. Apple has not said whether it blocks this attack.
  • โ†’ Know what a genuine Apple threat notification looks like: an alert on your iPhone’s lock screen and in Settings, an email to the address on your Apple Account, and a banner when you sign in at account.apple.com. Apple writes that these warnings never ask you to click links, open files, install apps or profiles, or give your account password or a verification code.

If you want to look for traces yourself, there is a free tool for it. During the Pegasus Project in 2021, Amnesty International’s Security Lab released the Mobile Verification Toolkit, MVT. It runs on your laptop. You make an encrypted backup of the iPhone with Finder on a Mac or iTunes on Windows, and MVT checks that backup against public lists of known spyware traces, with Pegasus and Predator among them. On Windows, the documentation points you to WSL, the Windows feature that runs Linux inside Windows.

1
2
3
4
pipx install mvt
mvt-ios download-iocs
mvt-ios decrypt-backup -d /path/to/decrypted /path/to/backup
mvt-ios check-backup --output /path/to/output/ /path/to/decrypted

MVT asks for the backup password itself, which keeps it out of your shell history. Its makers write that MVT “is not intended for end-user self-assessment,” and public indicators alone cannot prove that a phone is clean. A clean result means none of the known traces turned up, and nothing more. If you have good reason to worry, the project points you to Amnesty’s Security Lab and to Access Now’s Digital Security Helpline.

MVT runs in a Linux terminal, and on Windows through WSL, so it starts with being at home on that command line. My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.

โ†’ Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources:

Apple: security content of iOS 26.7.1 | Google Project Zero: A deep dive into an NSO zero-click iMessage exploit | Google Threat Intelligence: The proliferation of DarkSword | CISA: Known Exploited Vulnerabilities alert

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff โ€ข email โ€ข donate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I โ™ฅ open-source and Linux