Apple has patched an actively exploited flaw in CoreGraphics, the framework that handles path-based drawing and transformations on its platforms. The fix shipped September 28 in iOS 26.7.1, iPadOS 26.7.1 and macOS Tahoe 26.7.1, according to Apple’s security release notes.
The bug is tracked as CVE-2026-86950, an out-of-bounds write that Apple says it addressed with improved bounds checking. Apple’s notice says processing a maliciously crafted file may lead to arbitrary code execution. Apple also says it is aware of a report that the issue may have been exploited in “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” Apple credits Meta Product Security with the discovery and does not name the victims or the attacker.
Why it matters
A file-parsing flaw in a graphics framework needs little from the victim, because rendering a file is enough to reach the vulnerable code. Apple’s wording describes a narrow campaign against specific people, so most staff are unlikely to be the intended targets. The people who should worry are executives, lawyers, journalists and anyone whose phone would justify a custom attack.
Patches that arrive after exploitation has begun are now routine. We noted the same sequence when CISA confirmed active exploits for a flaw we had flagged. The measure that matters is how quickly a fix reaches every device you manage, as with the Roundcube bug exploited after its patch.
One original angle
Apple’s phrase “before iOS 27” ties the reported exploitation to devices that have not moved to the new major version. A mobile device management report grouped by major OS version shows who is still exposed, and which of those people are high-risk. Start there, push the updates, and confirm compliance for that group first.
Source: Apple Security Releases: iOS 26.7.1 and iPadOS 26.7.1