iOS 26.7.1 Patches CoreGraphics Zero-Day Used in Targeted Attacks - Security article on gikiewicz.com

Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026. The Apple security advisory identifies a CoreGraphics out-of-bounds write, CVE-2026-86950. Apple says processing a maliciously crafted file may lead to arbitrary code execution and quotes the advisory: “An out-of-bounds write issue was addressed with improved bounds checking.” The company says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

TL;DR: Apple’s September 28 advisory covers iOS 26.7.1 and iPadOS 26.7.1. It describes a CoreGraphics flaw that may allow arbitrary code execution when a maliciously crafted file is processed. Apple says the issue may have been exploited against specific targeted individuals on iOS versions before 27. The advisory states: “An out-of-bounds write issue was addressed with improved bounds checking.” Apple separately lists iOS 27.0.1 and iPadOS 27.0.1 on its security releases page.

What Did Apple Fix in iOS 26.7.1?

The CoreGraphics entry

Apple’s advisory names CoreGraphics and classifies the issue as an out-of-bounds write. Its impact statement says processing a maliciously crafted file may lead to arbitrary code execution. The advisory states: “An out-of-bounds write issue was addressed with improved bounds checking.” The advisory assigns the issue CVE-2026-86950 and gives the release date as September 28, 2026.

The advisory covers both iOS 26.7.1 and iPadOS 26.7.1. Apple’s availability list includes iPhone 11 and later, plus supported iPad models: iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later). Check the linked Apple notice for the exact model list and the wording of the security entry.

Which Other Apple Updates Addressed the Vulnerability?

Versions named in the coverage

Coverage from MacRumors and TidBITS says the same vulnerability was addressed in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, released on the same date. MacRumors lists those versions alongside iOS 26.7.1 and iPadOS 26.7.1 as updates addressing the issue.

The releases are distinct by platform and version. The reported update set is:

UpdatePlatformWhat the sources say
iOS 26.7.1iPhoneApple’s advisory lists the CoreGraphics issue
iPadOS 26.7.1iPadIncluded in Apple’s advisory for CVE-2026-86950
macOS Tahoe 26.7.1MacMacRumors and TidBITS report the vulnerability was addressed
macOS Sequoia 15.8.1MacMacRumors and TidBITS report the vulnerability was addressed
iOS 27.0.1 and iPadOS 27.0.1iPhone and iPadSeparate entries on Apple’s security releases page

Apple lists iOS 27.0.1 and iPadOS 27.0.1 as separate entries on its security releases page. The iOS 26.7.1 advisory identifies CVE-2026-86950 as affecting CoreGraphics.

What Does Apple Say About the Attack?

Apple’s wording

Apple’s notice says it is aware of a report that the issue may have been exploited in an “extremely sophisticated attack against specific targeted individuals” on versions of iOS before iOS 27. The wording is important: Apple reports a possibility of exploitation, rather than stating that the flaw was conclusively used in a broad campaign.

MacRumors reports Apple’s belief that the vulnerability had been used against a small number of people; it says the attack “wasn’t widespread.”

Is iOS 27.0.1 the Same Security Fix?

The iOS 27 releases are listed separately

The Apple advisory says the reported exploitation affected versions of iOS before iOS 27. Apple’s security releases page separately lists iOS 27.0.1 and iPadOS 27.0.1, while the iOS 26.7.1 advisory identifies CVE-2026-86950 in CoreGraphics.

Apple’s security releases page lists iOS 27.0.1 and iPadOS 27.0.1 as separate entries. The iOS 26.7.1 advisory identifies CVE-2026-86950 as a CoreGraphics out-of-bounds write and quotes the fix as improved bounds checking.

Which Devices Are Covered by the Apple Notice?

Availability and platform versions

Apple’s availability list for iOS 26.7.1 names iPhone 11 and later. For iPadOS 26.7.1, it lists iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later). The linked notice is the source for the full compatibility list.

MacRumors and TidBITS report macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 as the corresponding Mac updates addressing the vulnerability. These names and version numbers matter: the reported Mac releases are not macOS 27.0.1. Apple’s security releases page lists macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 with September 28 release dates.

What Should Users Do?

Recommendations in the reporting

9to5Mac recommends installing iOS 26.7.1 on iPhones that have not upgraded to iOS 27. MacRumors likewise advises users on iOS 26, iPadOS 26, macOS Tahoe, or macOS Sequoia to install the corresponding updates. Those recommendations match the branches named in the Apple advisory and in the release coverage.

Apple’s advisory says the reported exploitation affected versions of iOS before iOS 27. Its security releases page lists iOS 27.0.1 and iPadOS 27.0.1; the iOS 26.7.1 advisory names CVE-2026-86950. Check Apple’s notice for the update and device compatibility that apply to a given device.

Frequently Asked Questions

Questions about the update

What kind of vulnerability did iOS 26.7.1 fix?

Apple describes CVE-2026-86950 as an out-of-bounds write in CoreGraphics. Its impact statement says processing a maliciously crafted file may lead to arbitrary code execution; the advisory states: “An out-of-bounds write issue was addressed with improved bounds checking.”

Did Apple confirm that attackers used the flaw?

Apple says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before 27. MacRumors reports Apple’s belief that a small number of people were affected. The advisory’s wording is “may have been exploited.”

Does iOS 27.0.1 include the same CoreGraphics patch?

The Apple advisory describes the affected iOS versions as versions before iOS 27. Apple’s security releases page lists iOS 27.0.1 and iPadOS 27.0.1 separately; the iOS 26.7.1 advisory identifies CVE-2026-86950 in CoreGraphics.

Which other versions are reported to include the fix?

Apple’s notice covers iPadOS 26.7.1 as well as iOS 26.7.1. MacRumors and TidBITS report macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 as addressing the same vulnerability.

Summary

  • Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, with a CoreGraphics fix.
  • The Apple advisory identifies CVE-2026-86950, an out-of-bounds write that may allow arbitrary code execution when a maliciously crafted file is processed.
  • Apple says the issue may have been exploited in a sophisticated attack against specific targeted individuals on iOS versions before 27.
  • MacRumors and TidBITS report that macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 also address the vulnerability.
  • Apple lists iOS 27.0.1 and iPadOS 27.0.1 separately; the iOS 26.7.1 advisory identifies CVE-2026-86950 in CoreGraphics.

For version details and supported-device lists, use Apple’s security advisory and security releases page.