Cybersecurity 4 min read

Apple Patched an Exploited Flaw in iOS 26, Which Most iPhones Still Run

The CoreGraphics bug was used against targeted people on versions before iOS 27. Nearly 80% of iPhones were still on iOS 26, so iOS 26.7.1 is the update that matters.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 30 Sep 2026, 10:04 AM (SGT)
Share:
A hand holding an iPhone showing its lock screen A hand holding an iPhone showing its lock screen Photo by ductuyenpham on Pixabay
Advertisement

30 SEP 2026 — Apple released iOS 26.7.1 on 28 September to fix a flaw in CoreGraphics that it says may already have been used against specific people. The attacks it describes hit versions of iOS before iOS 27. That sounds like an old-phone problem, but it is not: most iPhones in use are still on iOS 26.

The bug is tracked as CVE-2026-86950. The US Cybersecurity and Infrastructure Security Agency added it to its list of exploited vulnerabilities the next day.

What Apple fixed

CoreGraphics is Apple's drawing layer for images, text and documents on screen. Apple's advisory says processing "a maliciously crafted file may lead to arbitrary code execution". The cause was an out-of-bounds write, where software writes data past the end of the memory set aside for it. Apple says it added better bounds checking.

Apple uses its usual wording for targeted spyware cases: it is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27".

Meta Product Security reported the flaw. Apple has not said who was targeted or who carried out the attacks.

CVE-2026-86950Out-of-bounds write in CoreGraphics
28 SeptiOS 26.7.1, iPadOS 26.7.1 and two macOS updates released
2 OctDeadline for US federal agencies to act
iPhone 11+Devices covered by the iOS 26.7.1 fix

Which devices need the update

Anyone on iOS 26 or iPadOS 26 should install 26.7.1. It covers the iPhone 11 and later and the iPads that run iPadOS 26. On the Mac, the same fix ships in macOS Tahoe 26.7.1 and in macOS Sequoia 15.8.1, which suggests the vulnerable code is not limited to phones even though Apple's description of the attacks mentions only iOS.

iOS 27, released on 14 September, is not affected by the flaw under attack. Apple also shipped iOS 27.0.1 on 28 September, but lists no security content for it.

Why the old version is the common one

The phrase "before iOS 27" covers most of the installed base. Nearly 80% of iPhone users were still on iOS 26, according to Apple's developer figures as reported by TechCrunch. A major iOS release takes months to reach most phones, and many people wait deliberately for the first bug fixes.

That makes the security release for the older version as important as the new version itself.

A second Meta report in six weeks

This is the second graphics-parsing flaw found by Meta's security team that Apple has fixed recently. In August, Apple patched an integer overflow in ImageIO, the code that turns image files into pixels, also reported by Meta. That one had no known exploitation.

Advertisement

File and image parsers keep recurring in these cases because a phone processes files it did not ask for, such as message attachments and web images, and a bug there can be reached without the owner doing much at all. Apple has not said how the CoreGraphics flaw was delivered.

What CISA's listing adds

CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 29 September. Its entry gives federal civilian agencies until 2 October to apply Apple's updates and marks the flaw for forensic triage, meaning agencies are asked to check for signs of compromise as well as patch.

For everyone else the action is simpler. Update to iOS 26.7.1, or move to iOS 27 if you were planning to, and update Macs on Tahoe or Sequoia. People who have reason to think they are targets of state-level spying can also turn on Lockdown Mode, Apple's setting that reduces what a phone will process from strangers.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement