Apple Fixes iPhone, iPad and Mac Flaw That May Have Been Exploited in Targeted Attacks

Update your iPhone, iPad and Mac now: Apple has fixed a flaw that could let attackers run code through a malicious file, and it may already have been exploited.

Apple Fixes iPhone, iPad and Mac Flaw That May Have Been Exploited in Targeted Attacks

Apple has released security updates for iPhones, iPads and Macs to fix a flaw that could let an attacker run their own code when a device processes a maliciously crafted file. Apple says the issue may already have been used in a highly targeted attack, so it is worth checking Software Update on every Apple device in the house.

The fix is included in iOS 26.7.1 and iPadOS 26.7.1, released on 28 September 2026. It is also in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

The flaw is tracked as CVE-2026-86950 and affects CoreGraphics. CoreGraphics is the Apple framework used across its operating systems and apps to display and process visual content such as images and PDFs.

According to Apple's security advisory, it is an out-of-bounds write issue, which Apple addressed with improved bounds checking. Processing a maliciously crafted file may lead to arbitrary code execution.

Apple said it is aware of a report that the issue may have been exploited in an "extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27. The company credited Meta Product Security with discovering and reporting the vulnerability.

According to The Hacker News, Apple has not said how many people were targeted, whether any of those attempts succeeded, or when the flaw was first exploited.

Pieter Arntz, Malware Intelligence Researcher at Malwarebytes, explained that this type of bug happens when software writes data beyond the limits of its allocated area of memory. He said this can overwrite other data, cause a crash, or even let an attacker take control of the affected process. He added that although the reported attack was highly targeted, "…other attackers could try to exploit the flaw now that it has been disclosed."

In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalogue on 29 September 2026. It required US federal agencies to apply the fixes by 2 October 2026.

On 1 October 2026, The Hacker News reported that security researchers had published the first public proof-of-concept for the flaw. It noted that the proof-of-concept does not demonstrate code execution.

The iOS and iPadOS update is available for the following devices:

  • iPhone 11 and later
  • iPad Pro 12.9-inch 3rd generation and later
  • iPad Pro 11-inch 1st generation and later
  • iPad Air 3rd generation and later
  • iPad 8th generation and later
  • iPad mini 5th generation and later

Mac users running macOS Tahoe or macOS Sequoia should install the matching update.

To update an iPhone or iPad, go to Settings, then General, then Software Update. You will see whether an update is available and be guided through installing it. You can also turn on Automatic Updates on the same screen.

On a Mac, click the Apple menu in the upper-left corner of the screen and choose System Settings, or System Preferences on older versions. Select General, then Software Update, and click Update Now if an update is available. Enter your administrator password if prompted, and keep the Mac plugged in and connected to the internet until the update finishes, as it may need to restart.

Follow our WhatsApp ChannelLive Alerts