Overview
- Apple released emergency updates Monday that fix CVE-2026-86950 in iOS/iPadOS 26.7.1 and macOS Tahoe/Sequoia 26.7.1 and 15.8.1 to stop an out-of-bounds write in CoreGraphics.
- The company credited Meta Product Security with reporting the flaw and said it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific iOS users while providing no public details about victims or delivery methods.
- CoreGraphics is the system graphics and PDF renderer, and the out-of-bounds write could allow arbitrary code execution when processing a maliciously crafted file, so plausible delivery paths include images or PDFs delivered by web pages, email, or messaging apps.
- Security vendors have urged users on affected OS branches to update immediately and told high-value targets and cryptocurrency holders to harden devices and assume risk because installing the patch does not undo prior data theft.
- Authorities and technical attribution remain limited for now, with iOS/macOS 27 releases appearing unaffected and CISA not yet listing the CVE in its Known Exploited Vulnerabilities catalog, so further investigation and vendor notices are likely to follow.