Overview
- Apple released security updates for iOS and iPadOS 26.7.1 and for macOS Tahoe 26.7.1 and Sequoia 15.8.1 to fix CVE-2026-86950 in the CoreGraphics framework.
- Apple credited Meta Product Security with reporting the bug and said it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific individuals, while providing no details on victims or delivery methods.
- The flaw is an out‑of‑bounds write in CoreGraphics that can lead to arbitrary code execution when the system processes a maliciously crafted image or PDF, making web pages, email attachments, and messaging previews plausible delivery paths.
- Security firms including SlowMist urged affected users to update quickly because device compromise can expose sensitive data such as private keys for crypto wallets, though no public proof links this CVE to confirmed wallet thefts.
- Authorities and defenders should watch for further disclosures and for a possible CISA KEV listing that would guide enterprise and government patch priorities, and all users on iOS 26 or supported macOS branches should install the available updates now.