MalwareBytes

Update your iPhone, iPad, or Mac: Flaw could run attackers’ code


Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27.

The fix is in iOS and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Check Software Update on each of your Apple devices and install the latest version offered.

Updates for your particular device

The table below shows which relevant updates are available and links to Apple’s security information for each one.

How to update your Apple devices

How to update your iPhone or iPad

To check if you’re using the latest software version, go to Settings > General > Software Update. You’ll see if an update is available and be guided through installing it.

Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.

Available update options on iPad

How to update macOS on any version

To update macOS on any supported Mac, use Software Update:

  • Click the Apple menu in the upper-left corner of your screen.
  • Choose System Settings (or System Preferences on older versions).
  • Select General in the sidebar, then click Software Update on the right. On older macOS, look for Software Update directly.
  • Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, read Apple’s instructions.
  • Enter your administrator password if prompted, then let your Mac finish the update. It may need to restart.
  • Make sure your Mac stays plugged in and connected to the internet until the update is done.

Technical details

The bug, CVE-2026-86950, affects CoreGraphics, an Apple framework used throughout its operating systems and apps to display and process visual content such as images and PDFs.

It’s an out-of-bounds write issue, which Apple addressed with improved bounds checking. This type of bug happens when software writes data beyond the limits of its allocated area of memory. It can overwrite other data in memory, interfere with the normal operation of the program, cause a crash, or even let an attacker take control of the affected process. In this case, processing a maliciously crafted file may lead to an attacker running their own code.

Apple says it is aware of a report that the issue may have been exploited in an “extremely sophisticated attack” against specific people using versions of iOS before iOS 27. Although the reported attack was highly targeted, other attackers could try to exploit the flaw now that it has been disclosed. 


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 



Source link