SAN FRANCISCO—Apple issued software updates on Sept. 28, 2026, for its mobile and desktop operating systems, patching a CoreGraphics vulnerability identified as CVE-2026-86950. The company confirmed the flaw may have been exploited in sophisticated, targeted attacks against users running versions of iOS prior to iOS 27.
The updates include iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. These patches address an out-of-bounds write issue within CoreGraphics, a key framework for graphics rendering across Apple's ecosystem.
An attacker could achieve arbitrary code execution on a vulnerable device by inducing a user to open a specially crafted file. Apple described the root cause as a memory bug where data is written beyond its allocated boundary. The fix includes improved bounds checking to prevent this.
Apple said in its advisory that it is aware of reports indicating active exploitation of this issue. The attacks were characterized as "extremely sophisticated" and directed at "specific targeted individuals" on older iOS versions.
Meta Product Security received credit from Apple for reporting the vulnerability.
The risk level for CVE-2026-86950 is rated as High. This assessment stems from the flaw's active exploitation and its potential for remote code execution through a manipulated file, posing a direct threat to user data and device integrity.
The iOS 26.7.1 and iPadOS 26.7.1 updates are available for a wide range of devices, including iPhone 11 and later models. The issue also affected macOS Tahoe and macOS Sequoia, receiving corresponding patches.
Apple's standard security protocol involves not disclosing or confirming security issues until investigations are complete and patches are released. This policy aims to protect customers by preventing premature disclosure that could aid attackers before fixes are widely available.