www.malwarebytes.com 29 Sept 2026, 10:35 UTC

Apple Fixes Exploited iPhone Flaw in Targeted Attacks

Apple Fixes Exploited iPhone Flaw in Targeted Attacks
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

APPLE has released updates for iPhones, iPads and Macs to fix CVE-2026-86950, a vulnerability in CoreGraphics, the framework used to process visual content including images and PDFs. The out-of-bounds write flaw could allow a maliciously crafted file to overwrite data in memory, potentially causing a crash or enabling an attacker to run code in the affected process.

Apple said it was aware of a report that the vulnerability may have been exploited in an “extremely sophisticated attack” targeting specific people using iPhones running versions of iOS before iOS 27. This confirms reported exploitation in a highly targeted attack, while the article warns that other attackers could attempt to use the flaw now that it has been disclosed.

The fixes are included in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. The iPhone and iPad update covers iPhone 11 and later, and specified iPad Pro, iPad Air, iPad and iPad mini models. Users should open Settings > General > Software Update on iPhones and iPads, or Apple menu > System Settings > General > Software Update on Macs, and install the latest version offered.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline