Apple Updates Older iOS, iPadOS and macOS Releases for CoreGraphics Flaw

Apple addresses a potentially exploited CoreGraphics vulnerability
Apple has released security updates for older versions of iOS, iPadOS and macOS to remediate CVE-2026-86950, an out-of-bounds write in the CoreGraphics component. The company said it is aware of a report that the flaw may have been used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
The vulnerability could allow arbitrary code execution when an affected device processes a maliciously crafted file. Apple said it resolved the issue with improved bounds checking and credited Meta Product Security with discovering and reporting it.
Updates cover supported Apple hardware and two macOS branches
The mobile fixes are included in iOS 26.7.1 and iPadOS 26.7.1. They apply to iPhone 11 and later; iPad Pro 12.9-inch, third generation and later; iPad Pro 11-inch, first generation and later; iPad Air, third generation and later; iPad, eighth generation and later; and iPad mini, fifth generation and later.
Apple also issued macOS Tahoe 26.7.1 for Macs running macOS Tahoe and macOS Sequoia 15.8.1 for Macs running macOS Sequoia. The advisory does not state how many people were targeted, whether any exploitation attempts succeeded, or when exploitation was first observed.
Why the disclosure warrants prompt patching
CoreGraphics is involved in processing graphical content, and Apple describes the attack path as a maliciously crafted file. That makes the remediation relevant to organisations that receive files through email, messaging, browsers, document workflows or other endpoint-facing channels.
Apple has flagged targeted exploitation in other 2026 advisories. In February, it patched CVE-2026-20700, a memory-corruption issue in dyld with a CVSS score of 7.8, stating that the bug had been weaponized in sophisticated cyber attacks.
For security and IT teams, the immediate business implication is to identify managed devices eligible for iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, prioritise deployment, and confirm patch compliance across the fleet.

