Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, a CoreGraphics vulnerability the company says may have been used in targeted attacks. The updates came out on September 28, 2026, along with matching fixes for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
The flaw is in CoreGraphics, a core Apple framework that handles graphics rendering. According to Apple, processing a maliciously crafted file may lead to arbitrary code execution. In practice, an attacker could run their own code on a vulnerable device by getting it to open a specially prepared file.
Apple described the root cause as an out-of-bounds write issue. This type of memory bug happens when software writes data past the edge of the memory area set aside for it. The company said it fixed the problem with improved bounds checking.
In its advisory, Apple stated: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
Apple credited Meta Product Security with reporting the vulnerability.
Devices Covered by the iOS and iPadOS Update
The iOS 26.7.1 and iPadOS 26.7.1 fix is available for iPhone 11 and later. On the iPad side, it covers:

- iPad Pro 12.9-inch (3rd generation and later)
- iPad Pro 11-inch (1st generation and later)
- iPad Air (3rd generation and later)
- iPad (8th generation and later)
- iPad mini (5th generation and later)
CVE-2026-86950 Also Reaches macOS
The issue is not limited to iOS and iPadOS. Apple published separate security notes for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, both released on September 28, 2026. Each describes the same CoreGraphics flaw, the same arbitrary code execution risk, and the same out-of-bounds write fix. Each also credits Meta Product Security.
The macOS notes repeat Apple’s statement that the bug may have been exploited against specific individuals on versions of iOS before iOS 27. The Tahoe update applies to macOS Tahoe, and the Sequoia update applies to macOS Sequoia.
Advisory Rates CVE-2026-86950 as High Risk
A separate advisory, also dated September 28, 2026, classifies the problem as a remote code execution vulnerability in Apple products. It warns that a remote attacker could exploit the flaw to trigger remote code execution on a targeted system.
The advisory rates the risk level as High for two reasons. The flaw is being exploited in an extremely sophisticated attack on specific targeted individuals running versions of iOS before iOS 27. A crafted file is also enough to achieve arbitrary code execution.
The advisory lists the following as affected:
- Versions prior to iOS 26.7.1 and iPadOS 26.7.1
- Versions prior to macOS Tahoe 26.7.1
- Versions prior to macOS Sequoia 15.8.1
It recommends that users visit the vendor’s website for details before installing and then apply the vendor’s fixes. The related Apple support pages are:
Apple’s Disclosure Approach
Apple says that, to protect customers, it does not disclose, discuss, or confirm security issues until it has investigated them and patches or releases are available. The company references vulnerabilities by CVE-ID when possible, as it did with CVE-2026-86950. Recent releases are listed on its security releases page, and more information is on its Product Security page.
Apple’s notes also state that information about products not made by Apple, or about independent websites it does not control, is provided without recommendation or endorsement. Apple directs users to contact those vendors for further details.
Since attackers have reportedly already used the flaw, owners of supported iPhones and iPads should install iOS 26.7.1 or iPadOS 26.7.1. Mac users should update to macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, depending on which version they run.

