Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026. The Apple security advisory identifies a CoreGraphics out-of-bounds write, CVE-2026-86950. Apple says processing a maliciously crafted file may lead to arbitrary code execution and quotes the advisory: “An out-of-bounds write issue was addressed with improved bounds checking.” The company says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
TL;DR: Apple’s September 28 advisory covers iOS 26.7.1 and iPadOS 26.7.1. It describes a CoreGraphics flaw that may allow arbitrary code execution when a maliciously crafted file is processed. Apple says the issue may have been exploited against specific targeted individuals on iOS versions before 27. The advisory states: “An out-of-bounds write issue was addressed with improved bounds checking.” Apple separately lists iOS 27.0.1 and iPadOS 27.0.1 on its security releases page.
What Did Apple Fix in iOS 26.7.1?
The CoreGraphics entry
Apple’s advisory names CoreGraphics and classifies the issue as an out-of-bounds write. Its impact statement says processing a maliciously crafted file may lead to arbitrary code execution. The advisory states: “An out-of-bounds write issue was addressed with improved bounds checking.” The advisory assigns the issue CVE-2026-86950 and gives the release date as September 28, 2026.
The advisory covers both iOS 26.7.1 and iPadOS 26.7.1. Apple’s availability list includes iPhone 11 and later, plus supported iPad models: iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later). Check the linked Apple notice for the exact model list and the wording of the security entry.
Which Other Apple Updates Addressed the Vulnerability?
Versions named in the coverage
Coverage from MacRumors and TidBITS says the same vulnerability was addressed in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, released on the same date. MacRumors lists those versions alongside iOS 26.7.1 and iPadOS 26.7.1 as updates addressing the issue.
The releases are distinct by platform and version. The reported update set is:
| Update | Platform | What the sources say |
|---|---|---|
| iOS 26.7.1 | iPhone | Apple’s advisory lists the CoreGraphics issue |
| iPadOS 26.7.1 | iPad | Included in Apple’s advisory for CVE-2026-86950 |
| macOS Tahoe 26.7.1 | Mac | MacRumors and TidBITS report the vulnerability was addressed |
| macOS Sequoia 15.8.1 | Mac | MacRumors and TidBITS report the vulnerability was addressed |
| iOS 27.0.1 and iPadOS 27.0.1 | iPhone and iPad | Separate entries on Apple’s security releases page |
Apple lists iOS 27.0.1 and iPadOS 27.0.1 as separate entries on its security releases page. The iOS 26.7.1 advisory identifies CVE-2026-86950 as affecting CoreGraphics.
What Does Apple Say About the Attack?
Apple’s wording
Apple’s notice says it is aware of a report that the issue may have been exploited in an “extremely sophisticated attack against specific targeted individuals” on versions of iOS before iOS 27. The wording is important: Apple reports a possibility of exploitation, rather than stating that the flaw was conclusively used in a broad campaign.
MacRumors reports Apple’s belief that the vulnerability had been used against a small number of people; it says the attack “wasn’t widespread.”
Is iOS 27.0.1 the Same Security Fix?
The iOS 27 releases are listed separately
The Apple advisory says the reported exploitation affected versions of iOS before iOS 27. Apple’s security releases page separately lists iOS 27.0.1 and iPadOS 27.0.1, while the iOS 26.7.1 advisory identifies CVE-2026-86950 in CoreGraphics.
Apple’s security releases page lists iOS 27.0.1 and iPadOS 27.0.1 as separate entries. The iOS 26.7.1 advisory identifies CVE-2026-86950 as a CoreGraphics out-of-bounds write and quotes the fix as improved bounds checking.
Which Devices Are Covered by the Apple Notice?
Availability and platform versions
Apple’s availability list for iOS 26.7.1 names iPhone 11 and later. For iPadOS 26.7.1, it lists iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later). The linked notice is the source for the full compatibility list.
MacRumors and TidBITS report macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 as the corresponding Mac updates addressing the vulnerability. These names and version numbers matter: the reported Mac releases are not macOS 27.0.1. Apple’s security releases page lists macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 with September 28 release dates.
What Should Users Do?
Recommendations in the reporting
9to5Mac recommends installing iOS 26.7.1 on iPhones that have not upgraded to iOS 27. MacRumors likewise advises users on iOS 26, iPadOS 26, macOS Tahoe, or macOS Sequoia to install the corresponding updates. Those recommendations match the branches named in the Apple advisory and in the release coverage.
Apple’s advisory says the reported exploitation affected versions of iOS before iOS 27. Its security releases page lists iOS 27.0.1 and iPadOS 27.0.1; the iOS 26.7.1 advisory names CVE-2026-86950. Check Apple’s notice for the update and device compatibility that apply to a given device.
Frequently Asked Questions
Questions about the update
What kind of vulnerability did iOS 26.7.1 fix?
Apple describes CVE-2026-86950 as an out-of-bounds write in CoreGraphics. Its impact statement says processing a maliciously crafted file may lead to arbitrary code execution; the advisory states: “An out-of-bounds write issue was addressed with improved bounds checking.”
Did Apple confirm that attackers used the flaw?
Apple says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before 27. MacRumors reports Apple’s belief that a small number of people were affected. The advisory’s wording is “may have been exploited.”
Does iOS 27.0.1 include the same CoreGraphics patch?
The Apple advisory describes the affected iOS versions as versions before iOS 27. Apple’s security releases page lists iOS 27.0.1 and iPadOS 27.0.1 separately; the iOS 26.7.1 advisory identifies CVE-2026-86950 in CoreGraphics.
Which other versions are reported to include the fix?
Apple’s notice covers iPadOS 26.7.1 as well as iOS 26.7.1. MacRumors and TidBITS report macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 as addressing the same vulnerability.
Summary
- Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, with a CoreGraphics fix.
- The Apple advisory identifies CVE-2026-86950, an out-of-bounds write that may allow arbitrary code execution when a maliciously crafted file is processed.
- Apple says the issue may have been exploited in a sophisticated attack against specific targeted individuals on iOS versions before 27.
- MacRumors and TidBITS report that macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 also address the vulnerability.
- Apple lists iOS 27.0.1 and iPadOS 27.0.1 separately; the iOS 26.7.1 advisory identifies CVE-2026-86950 in CoreGraphics.
For version details and supported-device lists, use Apple’s security advisory and security releases page.