Gadgets

Apple fixes iOS 26 flaw possibly exploited in targeted attacks

A malicious file could trigger the CoreGraphics bug. Apple credits Meta Product Security and says the reported attack targeted specific individuals.

Share
Apple's iOS 26 runs on iPhone 11 and later. Credit: Apple

Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix a CoreGraphics vulnerability that it says may have been exploited in an attack against specific targeted individuals.

Apple’s security notes describe the bug, tracked as CVE-2026-86950, as an out-of-bounds write issue. Processing a maliciously crafted file could let an attacker run arbitrary code on the device.

Apple credits Meta Product Security with reporting it and says it fixed the problem with improved bounds checking.

Apple calls the reported attack “extremely sophisticated” and says it hit versions of iOS before iOS 27. The company has not said who was targeted, who was behind the attack, or how many devices were affected.

The updates, released September 28, cover iPhone 11 and later, along with several iPad Pro, iPad Air, iPad, and iPad mini models. SecurityWeek reports that macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, released the same day, carry the same fix.

MacRumors noted that iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1, released September 28, list no CVE entries, and that Apple’s latest operating systems don’t appear to be affected.

Users still on iOS 26 or iPadOS 26 can install the update through Settings > General > Software Update.

Sources: Apple MacRumors SecurityWeek

Leave a Reply

Your email address will not be published. Required fields are marked *