Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in the CoreGraphics component that can lead to arbitrary code execution when processing a maliciously crafted file, addressed with improved bounds checking. Apple said it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27", and credited Meta Product Security with discovering and reporting the flaw — but offered no detail on how many individuals were targeted, whether any attempts succeeded, or when exploitation began. The affected builds cover iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later and iPad mini 5th generation and later, plus Macs running Tahoe or Sequoia. The disclosure continues Apple's pattern of patching memory-safety flaws in core frameworks while attributing exploitation only to small, targeted campaigns: in February it fixed a dyld memory-corruption issue (CVE-2026-20700, CVSS 7.8) on the same basis.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-29 |
| Source | The Hacker News |
| Reliability | Tier 2 |
| CVEs | CVE-2026-20700, CVE-2026-86950 |