Apple issues urgent iOS 26.7.1 update, warns of exploit in sophisticated targeted attack
Apple has issued an urgent security warning to iPhone users still on iOS 26 to update immediately to iOS 26.7.1.
The update, released on September 28 alongside iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, patches a critical zero-day flaw in CoreGraphics — Apple’s low-level framework that handles images, PDFs and graphics rendering.
Tracked as CVE-2026-86950, the vulnerability is an out-of-bounds write bug that could allow an attacker to execute arbitrary code just by getting the victim to open a maliciously crafted file.
Apple said it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” The company did not disclose who was targeted or how many users were affected.
The flaw was discovered and reported by Meta’s Product Security team, and fixed with improved bounds checking. Apple said devices running iOS 27 and iPadOS 27 are not affected.
The update applies to iPhone 11 and later, iPad Pro 11-inch 1st-gen and later, iPad Pro 12.9-inch 3rd-gen and later, iPad Air 3rd-gen and later, iPad 8th-gen and later, and iPad mini 5th-gen and later.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalogue.
Security researchers and blockchain firm SlowMist have also warned that the flaw could particularly put crypto wallet data at risk.



