Overview
- Apple released security updates on Monday that fix CVE-2026-86950 in CoreGraphics for iOS/iPadOS 26.7.1 and macOS Tahoe 26.7.1 and Sequoia 15.8.1.
- The flaw is an out-of-bounds write in the system image and PDF renderer that can corrupt memory or let an attacker run arbitrary code when a crafted file is processed.
- Apple credited Meta Product Security for reporting the bug and said it received a report the vulnerability may have been used in an “extremely sophisticated” targeted attack against iOS versions before iOS 27.
- Apple has not published technical details, victim counts, or confirmed delivery methods, though delivery via web pages, email or messaging previews is plausible because CoreGraphics is used system-wide.
- Security firms warned cryptocurrency users to update and to recreate wallets on a clean device if they suspect compromise, but there is no public evidence directly linking this specific CVE to confirmed wallet theft.