Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026 to fix a critical CoreGraphics zero-day (CVE-2026-86950) that it says may have been exploited in an extremely sophisticated attack against specifically targeted individuals.
CoreGraphics zero-day details
The vulnerability, tracked as CVE-2026-86950, exists in the CoreGraphics framework — the component that renders graphics, images and documents on iPhones and iPads — and stems from an out-of-bounds write. An attacker could craft a specially designed file that triggers the vulnerable code path when a device opens, previews, downloads or otherwise processes the file. If exploitation succeeds, the attacker may be able to execute arbitrary code within the affected process, potentially running unauthorized commands, installing components, accessing sensitive information or establishing a foothold for further compromise. Apple said it did not disclose technical details about the attackers, targeted victims, the malicious files used or whether the flaw was chained with other zero-days. The company addressed the issue by implementing improved bounds checking.
Affected devices and mitigation
The update is available for iPhone 11 and later models and for supported iPad systems: iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later). Apple urged users to install the updates as soon as possible and advised updating via Settings > General > Software Update. Organizations managing Apple fleets should verify patch deployment through their mobile device management platforms and identify devices that remain on older iOS or iPadOS releases.
Apple confirmed CVE-2026-86950 may have been exploited against specific individuals running iOS versions before iOS 27, a pattern commonly associated with spyware operations, intelligence collection, surveillance activity or attacks against high-value users such as journalists, activists, executives, government personnel and security researchers. CVE-2026-86950 was reported by Meta Product Security. Apple’s acknowledgment underscores the ongoing risk posed by zero-day vulnerabilities in file-processing components, particularly when used in targeted attacks.

