Software
Apple releases iOS 26.7.1 fixing one exploited CoreGraphics flaw
Apple released iOS 26.7.1 on 28 September 2026 with a single security fix for a CoreGraphics out-of-bounds write it says may have been exploited in targeted attacks.
Photo: MacRumorsKey points
Apple released iOS 26.7.1 on 28 September 2026 with one security fix, a CoreGraphics out-of-bounds write reported as exploited against targeted individuals.
Apple released iOS 26.7.1 on 28 September 2026 with one security fix, an out-of-bounds write in CoreGraphics that the company says may have been exploited in an extremely sophisticated attack against specific targeted individuals running versions of iOS before iOS 27. The same day Apple shipped iOS 27.0.1, iPadOS 27.0.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1 and visionOS 27.0.1.
The update matters because it is the only security entry in Apple's security support document for iOS 26.7.1, and it targets a flaw Apple believes was used against a small number of people. Devices that have not moved to iOS 27 get iOS 26.7.1 instead. Apple's wording points to targeted attacks, and the exploitation report covers versions of iOS before iOS 27.
What the update fixes
Apple's security support pages describe the issue as a CoreGraphics out-of-bounds write that could be exploited with a maliciously crafted file, allowing for arbitrary code execution. Apple says it fixed the flaw with improved bounds checking. Processing a maliciously crafted file may lead to arbitrary code execution, which means an attacker could run their own code on the device.
The mechanism is specific: CoreGraphics, the framework that renders images, writes past the end of a buffer when it handles a crafted file. Improved bounds checking adds a size test before that write, so the code stops instead of overwriting adjacent memory. Apple credits Meta Product Security for the discovery and assigns the flaw the identifier CVE-2026-86950.
CVE-2026-86950 is the only entry in the update's security document, and the affected component is CoreGraphics. Apple is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Apple gives no details on who was targeted, how the attacks worked, or how many devices were involved.
How the flaw works
Apple's stated policy is not to confirm security issues until patches are available. The company says the flaw was exploited in an extremely sophisticated attack on targeted individuals running older versions of iOS, and that its latest operating systems do not appear to be affected. The iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 updates released on 28 September 2026 have no published CVE entries.
The update reaches iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. That list matches the one Apple used for iOS 26.7, which landed alongside the public launch of iOS 27.
iOS 26.7, released two weeks before iOS 26.7.1, patched more than 80 security vulnerabilities across the Kernel, WebKit, Bluetooth and dozens of other frameworks. iOS 26.7.1 follows it with a much smaller patch of one entry. Anyone who has moved to iOS 27 can no longer downgrade to iOS 26, so this update is for people who chose to stay on iOS 26.
Who can install it now
Apple released a variety of software updates on 28 September 2026 focused on bug fixes and security updates, including iOS 26.7.1 for iPhone. iOS 27.0.1 and iPadOS 27.0.1 arrived the same day, alongside several macOS updates. iOS 27 and its companions, headlined by Siri AI, had launched two weeks earlier.
To install iOS 26.7.1, users open Settings, go to General, then tap Software Update, and automatic updates can be switched on in the same menu. Apple's release notes state the update contains security fixes for your iPhone. The company recommends installing the new updates as soon as possible, because now that the vulnerability is public, it could be further exploited against users who are not protected.
Frequently asked questions
What vulnerability does iOS 26.7.1 fix?
iOS 26.7.1 fixes one flaw, an out-of-bounds write in CoreGraphics identified as CVE-2026-86950. Processing a maliciously crafted file may lead to arbitrary code execution, and Apple addressed it with improved bounds checking.
Was the iOS 26.7.1 vulnerability actually exploited?
Apple says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Apple gives no details on who was targeted or how many devices were involved.
Which devices can install iOS 26.7.1?
iOS 26.7.1 is available for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
How this story was checked
- Fact-checked against 3 cited pages. 77 figures, dates and quotations in this story were found on the pages it cites; 1 passage that could not be checked was cut before publication.
- Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
- macrumors.comread and checked
- 9to5mac.comread and checked
- ithinkdiff.comread and checked
Written by Kaer from public reporting. Checked 29 September 2026.


