Apple’s CVE-2026-86950 is an out-of-bounds write flaw in CoreGraphics, the framework involved in processing graphics. A vulnerable iPhone, iPad or Mac could be exposed when it processes a maliciously crafted file, potentially allowing arbitrary code execution. Apple says it is aware of a report that the flaw may have been used in an extremely sophisticated attack against specific targeted individuals—not that all affected devices have been attacked.
1
2
3
9
Which Apple devices and software versions are affected?
The listed affected software is iOS and iPadOS versions before 26.7.1, macOS Sequoia versions before 15.8.1, and macOS Tahoe versions before 26.7.1. Apple’s security notices say the fixes are included in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. The notices were released on September 28, 2026.
1
2
3
Apple lists the affected iPhone and iPad families for its iOS and iPadOS notice as iPhone 11 and later; iPad Pro 12.9-inch (3rd generation and later); iPad Pro 11-inch (1st generation and later); iPad Air (3rd generation and later); iPad (8th generation and later); and iPad mini (5th generation and later).
1
Apple’s macOS advisories identify Sequoia and Tahoe software releases rather than a Mac-by-Mac model list. Check the macOS version installed on your Mac and install the applicable update offered for it.
2
3
Apple’s note about reported attacks specifies versions of iOS before iOS 27. That describes the versions in the exploitation report; it does not establish that every device running an older version was targeted.
1
9
How could a malicious file exploit the flaw?
The documented trigger is processing a maliciously crafted file. Apple says that could lead to arbitrary code execution, meaning an attacker could cause code to run on a vulnerable device. The available advisories do not identify a particular file format or spell out exactly how the file reaches or is processed by a target, so claims about a specific image, document, or delivery method would go beyond the evidence.
1
2
3
9
What do cybersecurity agencies say?
The U.S. National Vulnerability Database records Apple’s impact description, affected version ranges and statement that the flaw may have been exploited in highly sophisticated attacks against specific individuals. A security-news report also says the U.S. Cybersecurity and Infrastructure Security Agency added the CVE to its Known Exploited Vulnerabilities catalog; the supplied CISA results do not include an individual entry confirming that report, so that attribution should be treated as reported rather than independently verified here.
9
19
Indian media reports say CERT-In issued a high-severity alert and urged users to apply updates promptly. The material available here does not include the underlying CERT-In advisory, so its detailed wording and recommendations cannot be independently checked against the agency’s notice.
12
13
How to install the fix
Install the latest software update offered for each device. On iPhone or iPad, open Settings → General → Software Update. On Mac, open System Settings → General → Software Update. Apple’s security release list tracks updates and security notices.
1
2
3
4
Until a device is updated, avoid processing unexpected files, especially those from untrusted senders. That is a cautious interim step—not a substitute for installing the patch, and not evidence that one particular file type is responsible.
1
9
iOS 27.0.1 fixes separate iPhone issues
iOS 27.0.1’s listed bug fixes are separate from CVE-2026-86950. Apple says the update addresses unexpected restarts on iPhone 18 Pro and iPhone 18 Pro Max when Face ID fails to authenticate, a possible colour artifact in some 2× photos on a small number of those models, and an unresponsive touchscreen when Notification Center and Control Center are opened together.