Apple Issues an iPhone Update for a Flaw It Says May Have Been Used in Targeted Attacks

Apple has released iOS 26.7.1 and iPadOS 26.7.1, an update that fixes a flaw in CoreGraphics, the graphics software built into both systems. Apple's security advisory, published Sept. 28, 2026, identifies the flaw as CVE-2026-86950 and says the company is aware of a report that it may have been used in an attack on specific people.
The advisory's impact line reads: "Processing a maliciously crafted file may lead to arbitrary code execution." Handling the wrong file, in other words, could let someone else's code run on the device, and installing the update is what closes that off. Apple describes the fix as an out-of-bounds write issue addressed with improved bounds checking, and gives no further technical detail.
On the attack itself, the advisory says: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." That is a report the company says it has received rather than a finding it confirms, and the advisory names no targets and gives no other account of the attack.
The update is listed for iPhone 11 and later. On iPad, Apple lists iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Apple credits the report to Meta Product Security. The same page restates the company's standing practice on disclosure: it does not discuss or confirm a security issue until an investigation has finished and a patch or release is available.
