Image credit: Josh Kirschner/Techlicious via ChatGPT
Apple patched a flaw in iPhones, iPads, and Macs and says the bug may have been exploited in an "extremely sophisticated" attack against specific individuals using iOS. Apple disclosed the vulnerability, tracked as CVE-2026-86950, on September 28.
The bug sits in CoreGraphics, the part of Apple's software that processes images and other visual files across its platforms. Apple classifies it as an out-of-bounds write, where software writes data outside the memory set aside for it. According to Apple, processing a maliciously crafted file could let an attacker use this vulnerability to run their own code on the device.
Apple hasn't identified the attackers, the victims, or how the attack was delivered. Apple credits Meta Product Security with reporting the flaw, suggesting that the attack could have been routed through Facebook, Instagram, or WhatsApp.
The fix for this flaw is now available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
Journalists, activists, public officials, and others who are likely spyware targets should install the update first. Everyone else should install it too. On an iPhone or iPad, open Settings, tap General, then tap Software Update. On a Mac, open the Apple menu, choose System Settings, click General in the sidebar (scroll down if you don't see it), then click Software Update.
Read more: Four iOS 27 settings to change the day you install it