Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix CVE-2026-86950, a CoreGraphics security vulnerability that could allow arbitrary code execution. Apple said the issue may have been used against a limited group of targeted individuals running older iOS versions, as first reported by The Register.
The defect is an out-of-bounds write in the graphics framework, which processes files within Apple operating systems. A specially constructed file could cause the component to write data outside its intended memory bounds, potentially giving an attacker a way to execute code on the device. Apple fixed the problem by improving bounds checking.
Apple says the flaw saw targeted use
Apple characterized the incident in its security advisory as an extremely sophisticated attack aimed at specific people using older iOS releases. Meta Product Security reported the vulnerability to Apple.
Corresponding patches were also reported in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple’s current major operating-system releases were reported as unaffected, though owners of eligible devices should still install the available update.
The patch covers widely used Apple hardware
The mobile update applies to iPhone 11 models and later, along with several newer iPad lines. That matters because the weakness involves file handling in a system-level graphics component, and Apple issued the patch after possible exploitation had already occurred. Installing it closes a route through which a crafted file could compromise an affected device.
Apple has not identified the attackers or the people they targeted, and it has not disclosed how many devices may have been affected. The company and Meta have also not publicly explained how they discovered or used the vulnerability, which earlier iOS versions were exploited, or whether spyware or another tool played a role.
This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.