Apple has released iOS 26.7.1 and iPadOS 26.7.1 with a fix for CVE-2026-86950, a CoreGraphics vulnerability that may allow arbitrary code execution when a device processes a maliciously crafted file. Apple says the flaw was already exploited against selected targets before the patch became available.

Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Apple

The issue is an out-of-bounds write in CoreGraphics, a core Apple framework for processing and displaying graphical content. Apple addressed it with improved bounds checking. Meta Product Security reported the vulnerability, according to Apple’s official security documentation.

Apple has not identified the people targeted, the number of affected users, the delivery method for the malicious file, or whether spyware was involved. The company also has not said that this was a zero-click exploit, so the available disclosure does not establish whether a victim had to interact with the file.

PlatformVersion containing the fixReported attack scope
iPhoneiOS 26.7.1iOS versions earlier than iOS 27
iPadiPadOS 26.7.1iOS versions earlier than iOS 27
Mac running macOS TahoemacOS Tahoe 26.7.1Not specified
Mac running macOS SequoiamacOS Sequoia 15.8.1Not specified

Apple distributed the patch on September 28. For iPhones, iOS 26.7.1 is available beginning with the iPhone 11. The fix also reaches compatible iPad models across Apple’s main tablet lines:

  • iPad Pro
  • iPad Air
  • iPad
  • iPad mini

The company separately fixed the same vulnerability in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple says the observed attacks targeted releases earlier than iOS 27; iOS 27.0.1 is currently listed as the latest available version for compatible devices.

There is no indication that CVE-2026-86950 is being used in a mass campaign. Still, its confirmed exploitation makes the update particularly important for devices remaining on the iOS 26 branch. Users who may face elevated targeting risks can also use Apple’s Lockdown Mode, while further details on the attack chain remain undisclosed.

SOURCEsupport.apple.com
Previous articleREDMAGIC Astra 2 Brings Liquid Cooling to a 6.9mm Gaming Tablet