Apple’s iOS 26.7.1 / iPadOS 26.7.1 and matching macOS patches fix CVE-2026-86950, a CoreGraphics bug Apple says may have been exploited in targeted attacks before iOS 27.
Apple has published security updates for people still on the iOS 26 / iPadOS 26 and older macOS branches, closing a CoreGraphics flaw the company says may already have been exploited in highly targeted attacks.
This is a different job from yesterday’s iOS 27.0.1 Face ID reboot fix: Apple’s security notes for iOS 27.0.1 list no published CVE entries, while the parallel 26.7.1 train carries CVE-2026-86950.
About the security content of iOS 26.7.1 and iPadOS 26.7.1 (released 28 September 2026) describes an out-of-bounds write in CoreGraphics, fixed with improved bounds checking.
Impact (Apple’s wording): Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Matching CoreGraphics advisories also shipped for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Apple’s security releases index lists eligible hardware for iOS / iPadOS 26.7.1 as iPhone 11 and later, plus a broad set of iPads (iPad Pro 12.9-inch 3rd gen and later, 11-inch 1st gen and later, iPad Air 3rd gen and later, iPad 8th gen and later, iPad mini 5th gen and later).
Apple has not said how many people were targeted, whether any attacks succeeded, or which exact file types were used — treat the advisory as a prompt to update, not a technical deep-dive.
On iPhone or iPad: Settings → General → Software Update. On Mac: System Settings → General → Software Update. Prefer Wi‑Fi and a healthy battery (or power connected).
Coverage from MacRumors and The Hacker News matches Apple’s advisory language.
Bottom line: If you have not moved to the iOS 27 generation, iOS / iPadOS 26.7.1 (and the matching Tahoe / Sequoia builds) are the updates that close CVE-2026-86950, the CoreGraphics issue Apple links to a possible targeted, sophisticated exploit report. Install when you can.
Sources: Apple Support — iOS / iPadOS 26.7.1 security content; macOS Tahoe 26.7.1; macOS Sequoia 15.8.1; Apple security releases; MacRumors; The Hacker News.