iPhones still on iOS 26 need Apple’s new update after targeted attacks

By George Bailey   Published: 09/29/26   3 min read

Not everyone jumped to iOS 27 the week it shipped, and Apple’s latest fix is for them. On September 28 Apple released iOS 26.7.1 and iPadOS 26.7.1 with a single security fix: a CoreGraphics bug that Apple says may have been exploited in “an extremely sophisticated attack against specific targeted individuals” on versions of iOS before iOS 27.

Targeted usually means a short list: executives, journalists, people who travel, people with access. Those are also the people most likely to postpone a major OS upgrade.

“We’ll move to iOS 27 later” is a fine plan. It now needs iOS 26.7.1 in the meantime.

What happened

Apple’s security note for iOS 26.7.1 and iPadOS 26.7.1 lists one entry, CVE-2026-86950, an out-of-bounds write in CoreGraphics. Processing a maliciously crafted file may lead to arbitrary code execution. Apple fixed it with improved bounds checking and credited Meta Product Security with the report.

The same fix ships in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple did not say how many people were targeted, whether attacks succeeded, or when exploitation started. It released iOS 27.0.1 the same day for devices already on the new major version.

Why it matters

CoreGraphics draws and processes visual content across the system, so a “crafted file” can be something a person simply receives and opens. Apple’s wording points to a small number of chosen targets rather than a mass campaign, which is exactly why fleet dashboards can make this look minor. The risk concentrates on high-value people who deferred iOS 27.

What to do first

Forward this

If your iPhone is not on iOS 27 yet, please install iOS 26.7.1 today (Settings, General, Software Update). Apple says the bug it fixes may have been used in targeted attacks against specific people.

Details

Hunt / verify

Slack paste: Apple: devices staying on iOS/iPadOS 26 need 26.7.1 now (targeted exploitation per Apple); Macs to Tahoe 26.7.1 / Sequoia 15.8.1; execs and travelers first.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.