apple-bresa-exploited

Apple has fixed a security vulnerability in macOS that was already being exploited in attacks and that could give an attacker control over a computer simply by opening a file.

The vulnerability, tracked under CVE-2026-86950, is located in CoreGraphics—the component through which the operating system displays images, documents, and PDFs. A specially crafted file, whether received via email or downloaded, can execute code and take control of the computer simply by being opened.

Apple states that the vulnerability was exploited in “extremely sophisticated” attacks targeting specific individuals, and that it was reported by Meta’s security team. “Targeted” means this isn’t a widespread issue, so there’s no reason to panic, but the fix is available in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. On a Mac, the update can be installed from System Settings → General → Software Update and takes a few minutes.

For a small business, a Mac used for day-to-day work contains email, files, and access to the company's accounts. A computer compromised by an attacker thus becomes a key to the rest of the business—from messages and documents to accounts linked to the same email address.

What you need to do:

  • Update your Macs to macOS Tahoe 26.7.1 or Sequoia 15.8.1.
  • As a general rule, update work iPhones and iPads to the latest version as well.
  • If employees use their personal Apple devices for work, let them know to update as well.
  • Determine who is responsible for managing updates on company devices; in a company without its own IT department, a maintenance service applies them in the background.

A timely update is the most cost-effective form of security: a few minutes now, rather than an incident later.

Sources:

This article was generated with AI assistance.

Request a quote

← All news