The myth that “Macs don’t get viruses” keeps crumbling. Apple released patches for a vulnerability identified as CVE-2026-86950, an out-of-bounds write error in the CoreGraphics component that could allow arbitrary code execution when processing a manipulated file. The company acknowledged that the flaw could have been exploited in targeted attacks. The fixed versions are macOS Tahoe 26.7.1, macOS Sequoia 15.8.1 and iOS/iPadOS 26.7.1.
It is not an isolated case. In its September update alone, Apple fixed 273 vulnerabilities, a volume that, according to the Zero Day Initiative, reflects the new normal of AI-assisted flaw discovery. Among them stands out a critical Bluetooth flaw (9.8 out of 10) that allows remote code execution with no privileges and no user interaction.
AI is also on the attackers’ side. In January, the firm Mosyle detected what appears to be the first sample of Mac malware found in circulation with code generated by AI models, distributed through a fake Grok app. And according to Moonlock’s mid-year report, impersonations of AI developer tools are already the second most used disguise for malware, behind only pirated Adobe installers.
There is a reason attackers are looking at the Mac: users of AI tools and “vibe coding” are concentrated on macOS and tend to hold higher-value credentials, such as SSH keys, cloud tokens and cryptocurrency wallets, as a Pillar Security researcher explained.
What to do
Update right away from System Settings > General > Software Update, and download AI tools only from their official sites, not from search-engine ads or shared links. And watch out: if a website or an “AI chat” asks you to paste a command into Terminal, be suspicious.
Sources
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks, The Hacker News, September 28, 2026.
- The Apple Security Update Review for September 2026, Zero Day Initiative.
- Mosyle identifies one of the first known AI-assisted Mac malware threats, 9to5Mac, January 9, 2026.
- Mid-2026 macOS threat report, Moonlock.
- ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers, The Hacker News, March 2026.
Written by Mamífero. Edited by Rodrigo Cornejo. See how we select and verify each note.



