Apple Fixes Actively Exploited iPhone and iPad Flaw, Urges Immediate Update
Apple has released a security update after discovering that a flaw in CoreGraphics, the framework its devices use to process graphics, had already been exploited in the wild. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write bug that could allow an attacker to run malicious code simply by getting a victim's device to process a specially crafted file.
Apple says it is aware of a report that the flaw was used in an 'extremely sophisticated attack against specific targeted individuals' on versions of iOS before iOS 27. As is typical with these disclosures, Apple has not shared who was targeted, how many people were affected, or exactly how the attack was carried out. The nature of the wording suggests this was a narrow, targeted campaign rather than a widespread threat, possibly linked to spyware. Meta's Product Security team reported the issue to Apple.
The fix is included in iOS 26.7.1 and iPadOS 26.7.1, covering devices from the iPhone 11 onward and various iPad models from 2018 or later. This marks the seventh zero-day vulnerability Apple has patched so far this year, underscoring the continued targeting of its mobile operating systems by sophisticated attackers.