Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address a critical zero day vulnerability that was reportedly exploited in highly sophisticated attacks targeting a limited number of individuals. The security flaw, identified as CVE 2026 86950, affects the CoreGraphics framework, one of the core components responsible for rendering graphics, images, and documents across Apple devices. According to Apple, the vulnerability may have been used against specifically selected targets running versions earlier than iOS 27, highlighting the importance of installing the latest software updates without delay. The company made the security patches available on September 28, 2026, for supported iPhone and iPad models and encouraged users as well as enterprise administrators to ensure devices are updated as soon as possible.
The vulnerability exists because of an out of bounds write issue within the CoreGraphics framework. Memory safety flaws of this type occur when software writes data beyond the allocated memory boundaries, creating an opportunity for malicious actors to influence the application’s behavior. Apple stated that an attacker could exploit the flaw by persuading a target to process a specially crafted file. The malicious file could be opened, previewed, downloaded, or otherwise processed through vulnerable applications, potentially triggering the vulnerable code path. If successfully exploited, the issue could result in arbitrary code execution within the affected process, allowing unauthorized code to run on the device. Depending on the application involved and any additional vulnerabilities available, such an attack could provide access to sensitive information, install malicious components, or establish a foothold for further compromise. Apple has not disclosed technical details regarding the attack chain, the files used, or the identity of the individuals behind the activity while investigations continue and users deploy the available security updates.
Apple noted that the attacks appeared to be highly targeted rather than part of a widespread campaign. While the company did not attribute the activity to any specific group or operation, targeted exploitation of zero day vulnerabilities is often associated with surveillance campaigns directed at selected individuals, including journalists, government officials, executives, security researchers, activists, and other high profile users. By limiting technical disclosures, Apple aims to reduce the risk of additional exploitation while users update their devices. The company also confirmed that the vulnerability was reported by Meta Product Security, reflecting continued collaboration between technology companies and security researchers to identify and address serious software flaws before they can affect a broader user base.
To mitigate the issue, Apple implemented improved bounds checking within the affected component to prevent software from writing data outside valid memory locations. The security update is available for iPhone 11 and later models, including supported iPad Pro 12.9 inch models from the third generation onward, iPad Pro 11 inch models from the first generation onward, iPad Air from the third generation onward, iPad from the eighth generation onward, and iPad mini from the fifth generation onward. Users can install the update through the Software Update section in the device settings, while organizations managing Apple devices are advised to verify deployment through their mobile device management platforms and identify systems that remain on older software versions. Timely installation of these updates is considered an important step in reducing exposure to active exploitation and strengthening the security posture of Apple devices against sophisticated attacks.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.