Apple has shipped emergency updates for iPhones, iPads and Macs to fix a flaw in its CoreGraphics framework that it says may already have been used against real people. According to Apple's security notes, released on September 28, CVE-2026-86950 means that processing a maliciously crafted file may lead to arbitrary code execution. Put simply, an attacker who gets a target's device to handle a booby-trapped file could run code of their choosing on it.
Apple says it is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." That is the wording Apple reserves for targeted, high-end operations rather than mass exploitation. The bug was reported to Apple by Meta Product Security. Hong Kong's HKCERT rated it High Risk in a bulletin the following day.
One graphics bug, three operating systems
The same fix lands in three releases:
- iOS 26.7.1 and iPadOS 26.7.1, for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later (advisory)
- macOS Tahoe 26.7.1 (advisory)
- macOS Sequoia 15.8.1 (advisory)
Apple describes the flaw only as an out-of-bounds write, a memory-safety bug in which software writes data past the end of the space it was given, and says it was "addressed with improved bounds checking." CoreGraphics is the framework Apple's platforms use to draw and render graphics and documents, which is why one fix is going out to phones and desktops alike.
What Apple has not said
The advisories are brief even by Apple's standards. They carry no CVSS score, do not name the attacker or the people targeted, and do not say what type of file was used or how it reached victims. The exploitation Apple is aware of is tied to iOS versions older than iOS 27, which arrived earlier this month with a 257-flaw security release. The macOS notes repeat the same iOS wording and do not say whether any Mac was attacked. Meta has not published anything on how it found the bug.
Install 26.7.1 or Sequoia 15.8.1 now
Anyone still on the iOS 26 or iPadOS 26 line should install 26.7.1 from Settings, General, Software Update. Mac users should move to macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1. Organizations that manage Apple fleets should push these updates ahead of routine patch cycles, since Apple itself acknowledges a report of in-the-wild use.
People at elevated risk, such as journalists, activists, lawyers and officials, should also keep an eye out for Apple's threat notifications, which now appear on the Lock Screen, and consider Lockdown Mode, the hardening setting Apple offers for exactly this kind of targeted threat.
Apple usually says little until a fix is widely installed, and more detail may follow. What it has already said is enough to act on: a file-handling bug, a sophisticated attacker, and a patch that is available today.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.