Apple has released an urgent security update for iPhones, iPads and Macs that have not moved to this month’s newest operating systems. The company says the underlying flaw, CVE-2026-86950, may already have been used in an “extremely sophisticated attack” against specific people running versions of iOS older than iOS 27.
The fix arrived September 28 in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Anyone staying on those operating-system generations should install the update now rather than treating it as a routine point release. Apple’s own June usage figures showed that 79% of active iPhones were still on iOS 26, making the older branch far from obsolete when the patch landed.
What Apple disclosed about CVE-2026-86950
The flaw sits in CoreGraphics, a system framework used to render two-dimensional graphics, images and documents across Apple platforms. According to Apple’s security advisory, processing a maliciously crafted file could trigger arbitrary code execution. The technical cause was an out-of-bounds write, which Apple addressed by adding stronger bounds checks.
An out-of-bounds write lets software place data outside the memory area allocated for it. In a successful exploit, that corruption can redirect execution into attacker-controlled code. Because CoreGraphics participates in everyday rendering, the risky file does not need to look like an app installer. Apple has not disclosed the file type, delivery route, exploit chain, attacker or number of victims, so claims about a specific message, website or spyware vendor would be premature.
Meta Product Security received credit for reporting the issue. Apple’s wording indicates observed or credibly reported exploitation, but it also describes the campaign as targeted rather than broadly distributed. That distinction is useful for triage, not a reason to delay: public disclosure gives other attackers a clear vulnerability target even though exploit details remain private.
Which devices and versions need the update
For iPhone and iPad users remaining on the 26.x branch, the fixed releases are iOS 26.7.1 and iPadOS 26.7.1. Apple lists support for iPhone 11 and later; iPad Pro 12.9-inch third generation and later; iPad Pro 11-inch first generation and later; iPad Air third generation and later; iPad eighth generation and later; and iPad mini fifth generation and later.
Mac users should install macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, depending on the branch their Mac is running. Apple also issued iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 on September 28, but its security-release index lists no published CVE entries for those updates. Apple’s advisory specifically ties the known targeted exploitation to iOS versions before iOS 27.
How to check and install the fix
- On an iPhone or iPad, open Settings > General > Software Update.
- If the device remains on iOS or iPadOS 26, verify that the offered version is 26.7.1 or later, then install it.
- On a Mac, open System Settings > General > Software Update. Install macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, or a newer supported release.
- After the restart, return to the version screen and confirm the installed number. Do not rely only on automatic-update settings; staged rollouts, low storage, low battery and device-management deferrals can leave a device waiting.
Organizations should query their device-management inventory for the exact OS build rather than counting an update command as success. Prioritize executives, journalists, activists, researchers, political staff, incident responders and anyone who has previously received an Apple threat notification, since Apple’s description points to a selective campaign.
What high-risk users should do beyond patching
Installing the update closes the known memory-corruption flaw, but it does not establish whether a previously exposed device was compromised. A person who receives an Apple threat notification, notices unexplained configuration profiles or believes they were specifically targeted should preserve the alert, avoid deleting potential evidence and contact a qualified incident-response or digital-forensics service.
Apple’s Lockdown Mode can reduce the attack surface for people at elevated risk, although Apple has not said whether it blocks this particular exploit. It should complement the patch, not replace it.
The same principle applies to corporate fleets: update first, then separately investigate devices with credible targeting signals. A clean-looking phone after reboot is not proof that an earlier compromise never occurred.
A separate zero-click issue is not the same bug
CVE-2026-86950 should not be confused with CVE-2026-86869, a different Apple flaw disclosed earlier in September. Security researchers described that earlier issue as a zero-click iMessage path capable of escaping BlastDoor protections. The new CoreGraphics advisory does not say that CVE-2026-86950 is zero-click, nor does it identify Messages as the delivery channel.
For most users, the action is straightforward: if Settings shows iOS or iPadOS 26.7 or earlier, or a Mac is still on an unpatched Tahoe or Sequoia build, update it today.