30 SEP 2026 — Apple released iOS 26.7.1 on 28 September to fix a flaw in CoreGraphics that it says may already have been used against specific people. The attacks it describes hit versions of iOS before iOS 27. That sounds like an old-phone problem, but it is not: most iPhones in use are still on iOS 26.
The bug is tracked as CVE-2026-86950. The US Cybersecurity and Infrastructure Security Agency added it to its list of exploited vulnerabilities the next day.
What Apple fixed
CoreGraphics is Apple's drawing layer for images, text and documents on screen. Apple's advisory says processing "a maliciously crafted file may lead to arbitrary code execution". The cause was an out-of-bounds write, where software writes data past the end of the memory set aside for it. Apple says it added better bounds checking.
Apple uses its usual wording for targeted spyware cases: it is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27".
Meta Product Security reported the flaw. Apple has not said who was targeted or who carried out the attacks.
Which devices need the update
Anyone on iOS 26 or iPadOS 26 should install 26.7.1. It covers the iPhone 11 and later and the iPads that run iPadOS 26. On the Mac, the same fix ships in macOS Tahoe 26.7.1 and in macOS Sequoia 15.8.1, which suggests the vulnerable code is not limited to phones even though Apple's description of the attacks mentions only iOS.
iOS 27, released on 14 September, is not affected by the flaw under attack. Apple also shipped iOS 27.0.1 on 28 September, but lists no security content for it.
Why the old version is the common one
The phrase "before iOS 27" covers most of the installed base. Nearly 80% of iPhone users were still on iOS 26, according to Apple's developer figures as reported by TechCrunch. A major iOS release takes months to reach most phones, and many people wait deliberately for the first bug fixes.
That makes the security release for the older version as important as the new version itself.
A second Meta report in six weeks
This is the second graphics-parsing flaw found by Meta's security team that Apple has fixed recently. In August, Apple patched an integer overflow in ImageIO, the code that turns image files into pixels, also reported by Meta. That one had no known exploitation.
File and image parsers keep recurring in these cases because a phone processes files it did not ask for, such as message attachments and web images, and a bug there can be reached without the owner doing much at all. Apple has not said how the CoreGraphics flaw was delivered.
What CISA's listing adds
CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 29 September. Its entry gives federal civilian agencies until 2 October to apply Apple's updates and marks the flaw for forensic triage, meaning agencies are asked to check for signs of compromise as well as patch.
For everyone else the action is simpler. Update to iOS 26.7.1, or move to iOS 27 if you were planning to, and update Macs on Tahoe or Sequoia. People who have reason to think they are targets of state-level spying can also turn on Lockdown Mode, Apple's setting that reduces what a phone will process from strangers.