Skip to content
See the World Through ScienceA project of ALLATRA

Apple Issues an iPhone Update for a Flaw It Says May Have Been Used in Targeted Attacks

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Two Apple smartphones lie side by side on a gray surface, one showing its dark back and camera module, the other a lit screen with an Apple logo.
An earlier generation of the hardware the update covers, back and front. Apple's affected list runs from iPhone 11 onward (illustrative)."IPhone 15 pro" by Ka Kit Pang, via wikimedia, CC-BY-SA-4.0 · CC-BY-SA-4.0

Apple has released iOS 26.7.1 and iPadOS 26.7.1, an update that fixes a flaw in CoreGraphics, the graphics software built into both systems. Apple's security advisory, published Sept. 28, 2026, identifies the flaw as CVE-2026-86950 and says the company is aware of a report that it may have been used in an attack on specific people.

The advisory's impact line reads: "Processing a maliciously crafted file may lead to arbitrary code execution." Handling the wrong file, in other words, could let someone else's code run on the device, and installing the update is what closes that off. Apple describes the fix as an out-of-bounds write issue addressed with improved bounds checking, and gives no further technical detail.

On the attack itself, the advisory says: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." That is a report the company says it has received rather than a finding it confirms, and the advisory names no targets and gives no other account of the attack.

The update is listed for iPhone 11 and later. On iPad, Apple lists iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

Apple credits the report to Meta Product Security. The same page restates the company's standing practice on disclosure: it does not discuss or confirm a security issue until an investigation has finished and a patch or release is available.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Apple Issues an iPhone Update for a Flaw It Says May Have Been Used in Targeted Attacks

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.