Apple patches an exploited CoreGraphics flaw: push iOS 26.7.1, iPadOS 26.7.1 and the macOS updates to managed devices
EditorialBy TrustList Editorial
Apple released iOS and iPadOS 26.7.1 and macOS updates on 28 September 2026 to fix CVE-2026-86950, a CoreGraphics out-of-bounds write that Apple says may have been exploited in an extremely sophisticated attack on specific people.
About Apple patches an exploited CoreGraphics flaw: push iOS 26.7.1, iPadOS 26.7.1 and the macOS updates to managed devices
Apple patches an exploited CoreGraphics flaw: push iOS 26.7.1, iPadOS 26.7.1 and the macOS updates to managed devices
28 September 2026 — Apple released iOS 26.7.1 and iPadOS 26.7.1 on 28 September 2026, with matching updates for macOS, to fix CVE-2026-86950, a vulnerability in CoreGraphics, the system framework that draws images and documents. Apple says: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." The flaw was reported by Meta's product security team.
The vulnerability
- Impact: processing a maliciously crafted file may lead to arbitrary code execution.
- Cause: an out-of-bounds write, fixed with improved bounds checking.
- Devices: iPhone 11 and later; iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later). Apple's security-releases index lists the macOS Tahoe 26.7.1 and macOS Sequoia updates released the same day.
Apple does not say who was targeted or how. A targeted attack of this kind makes patching most urgent for the people most likely to be singled out.
Who is affected
Organisations that manage iPhones, iPads and Macs, and especially those whose senior staff, legal, finance or communications teams, or employees travelling in high-risk regions use Apple devices still on the 26.x line. Devices already on iOS 27 are not described as affected by the exploitation report.
What to do
- In your mobile-device-management tool, require iOS and iPadOS 26.7.1 (or iOS 27) and the matching macOS updates, and set a short deadline.
- Start with executives and other high-risk users, and with devices that open files from outside the organisation.
- Check the MDM compliance report for devices stuck on older versions, including devices that cannot run iOS 27 and must stay on 26.x.
- For staff at particular risk, consider Apple's Lockdown Mode.
Sources
- Apple: About the security content of iOS 26.7.1 and iPadOS 26.7.1 — 28 September 2026
- Apple: About the security content of macOS Tahoe 26.7.1 — 28 September 2026
- Apple security releases (read 29 September) — 29 September 2026
Categories & features
- United States of America
- California
- Cupertino, Ca
- Cybersecurity
- Mobile Device Management Software
- Endpoint Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United States of AmericaThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.