Apple Patches Exploited CoreGraphics Flaw in iOS 26.7.1 Update

2 min read
Source: 9to5Mac
Apple Patches Exploited CoreGraphics Flaw in iOS 26.7.1 Update
Photo: 9to5Mac
TL;DR

Apple released iOS 26.7.1, iPadOS 26.7.1, and macOS updates to patch a critical CoreGraphics vulnerability (CVE-2026-86950) that was actively exploited in targeted attacks. The update addresses an out-of-bounds write issue allowing arbitrary code execution via malicious files. While the latest iOS 27 updates are not affected, users on older versions are urged to update immediately.

Key points

  • Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 on September 28, 2026.
  • The updates address CVE-2026-86950, a CoreGraphics out-of-bounds write vulnerability that could lead to arbitrary code execution.
  • Apple confirmed the flaw was exploited in 'extremely sophisticated' attacks against specific individuals on pre-iOS 27 versions.
  • The vulnerability was discovered and reported by Meta Product Security.
  • iOS 27.0.1 and other latest OS updates do not contain this specific CVE, indicating they are not affected.
  • The update is available for iPhone 11 and later, along with compatible iPad and Mac models.

Background

This update follows a series of security-focused releases for the iOS 26 branch, including iOS 26.6.1 in August and iOS 26.7 in September. These updates were designed to provide security patches for users who had not yet upgraded to the major iOS 27 release, which launched in mid-September 2026 with over 100 security fixes.

How outlets are covering it

9to5Mac and MacRumors both emphasize the urgency of updating for users still on iOS 26, noting that the vulnerability was actively exploited. The Hacker News highlights that Apple provided no details on the scope or success of the attacks, only confirming it was 'extremely sophisticated.' MacRumors notes that while the attack wasn't widespread, the public disclosure of the flaw increases the risk for unpatched devices. All sources agree that the latest iOS 27 updates are not affected by this specific issue.

Why it matters

The active exploitation of a critical vulnerability in older OS versions poses a significant security risk for users who have not upgraded to iOS 27. The update is crucial for mitigating targeted attacks that could lead to arbitrary code execution, potentially compromising device integrity and user data.

What to watch

Users should immediately install iOS 26.7.1 or upgrade to iOS 27 to ensure protection against the exploited CoreGraphics vulnerability. Apple may release further updates as new vulnerabilities are discovered, but this patch is critical for current iOS 26 users.

Share this article

Want the full story? Read the original reporting

Read on 9to5Mac