---
title: Apple addresses critical security vulnerability in iOS and macOS
url: https://www.dataloco.com/en/apple-addresses-critical-security-vulnerability-in-ios-and-macos
published: 2026-10-01T20:20:30+00:00
language: en
section: Security
source: https://www.dailysecu.com/news/articleView.html?idxno=208631
organizations: coregraphics, cve-2026-86950, apple, meta
publisher: Dataloco
---

# Apple addresses critical security vulnerability in iOS and macOS

Apple has patched a security vulnerability that allows the execution of arbitrary code through malicious files on iPhone, iPad, and Mac operating systems. The company indicated that the vulnerability may have already been exploited in sophisticated cyberattacks targeting specific individuals.

The vulnerability, identified as CVE-2026-86950, arises from an out-of-bounds write issue in the CoreGraphics component responsible for handling graphic content in Apple operating systems. If an attacker can induce a victim's device to process specially crafted files, they may alter memory areas abnormally, potentially leading to arbitrary code execution. Apple resolved the issue by strengthening memory boundary checks. The vulnerability was discovered and reported to Apple by Meta's product security team.

A key aspect of this security update is the potential for actual targeted attacks. Apple has acknowledged reports suggesting that CVE-2026-86950 may have been exploited in very sophisticated attacks aimed at specific individuals using versions of iOS prior to 27.

However, there is currently no evidence suggesting that widespread attacks have occurred. Apple did not disclose information regarding the targets, extent of damage, success of the attacks, initial exploitation time, or the attackers involved.

This language suggests a focus on targeted attacks rather than general large-scale cyberattacks, emphasizing the possibility of attacks aimed at specific people, including journalists, human rights activists, and corporate or government officials. Zero-day vulnerabilities in Apple products have been consistently discovered as attack vectors in commercial spyware campaigns.

The vulnerability has been patched in iOS 26.7.1 and iPadOS 26.7.1, released on September 28, and affects devices such as iPhone 11 and newer, iPad Pro 12.9-inch (3rd generation and later), and iPad Air (3rd generation and later). The same vulnerability has been addressed in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

Given Apple's official mention of the potential for targeted attack exploitation, users of the affected operating systems are urged not to delay updates, and enterprise security personnel should verify the operating system versions on work devices and check for patch application.

## This story in other languages

- [עברית](https://www.dataloco.com/he/story-42)
- [Svenska](https://www.dataloco.com/sv/apple-utfardar-sakerhetsuppdatering-for-iphone-och-mac)
- [Norsk](https://www.dataloco.com/no/apple-oppdaterer-iphone-og-mac-med-sikkerhetsoppdatering)
- [Português (Brasil)](https://www.dataloco.com/pt-br/apple-lanca-atualizacao-de-seguranca-urgente-para-iphone-e-mac)
