Apple has released security updates for older versions of iOS, iPadOS, and macOS to address a vulnerability that it says may have been exploited in targeted attacks.

Tracked as CVE-2026-86950, the flaw affects the CoreGraphics component and is classified as an out-of-bounds write vulnerability. Apple said the issue could allow arbitrary code execution when the device processes a specially crafted file.

The company fixed the vulnerability with improved bounds checking and credited Meta Product Security for reporting the issue.

Apple said it is aware of reports that the vulnerability may have been exploited in an “extremely sophisticated attack” targeting specific individuals running versions of iOS before iOS 27. However, the company did not disclose how many people may have been targeted, whether the attacks were successful, or when exploitation of the vulnerability was first detected.

The security issue has been fixed in iOS 26.7.1 and iPadOS 26.7.1 for supported devices, including iPhone 11 and later, as well as several generations of iPad Pro, iPad Air, iPad, and iPad mini.

Apple has also released macOS Tahoe 26.7.1 for Macs running macOS Tahoe and macOS Sequoia 15.8.1 for systems running macOS Sequoia.

This is not the first exploited Apple vulnerability addressed this year. In February, Apple patched a memory corruption flaw in its dynamic linker, tracked as CVE-2026-20700, which the company said had also been used in sophisticated cyberattacks.


Buy ExpressVPN with PayPal or Credit Card

Advertisement
READ
Canada Opens Investigation Into IDScan.net Data Breach