Apple has released iOS 26.7.1 and iPadOS 26.7.1 with a fix for a CoreGraphics vulnerability that may already have been used against a small number of people. Anyone keeping an eligible device on the iOS 26 branch should install the update promptly.
In its security notice for iOS 26.7.1, Apple says processing a maliciously crafted file could lead to arbitrary code execution. The company is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals using versions of iOS released before iOS 27.
What Apple fixed in iOS 26.7.1
The issue is an out-of-bounds write in CoreGraphics, the system framework Apple platforms use to draw and process visual content. Apple addressed it with improved bounds checking and assigned it CVE-2026-86950. Meta Product Security received credit for reporting the vulnerability.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Apple’s wording does not mean every iPhone running iOS 26 was attacked. It describes a highly targeted campaign and does not identify the attackers, the delivery method, or the people affected. However, disclosure of the bug makes installing the patch important even for users who are unlikely to have been selected for the original operation.
The update supports iPhone 11 and later. Its iPad counterpart covers iPad Pro 12.9-inch models from the third generation, every 11-inch iPad Pro, iPad Air from the third generation, iPad from the eighth generation, and iPad mini from the fifth generation.
How to install the security update
Open Settings, select General, and tap Software Update. Back up important data before installing, then keep the iPhone or iPad connected to power if the battery is low. Apple’s security releases index lists the update as released on September 28, 2026.
The disclosure follows an earlier stretch in which Apple’s public security notes did not identify a newly exploited iPhone flaw. MacObserver maintains context on Apple’s separate security update branches. Users should install the version offered for their device rather than assuming a newer numbered operating system is the only protected option.
Discussion