Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, to fix a vulnerability in CoreGraphics. Apple says the flaw may allow arbitrary code execution when a device processes a maliciously crafted file, and that possible exploitation was reported against specific targeted individuals on iOS versions before iOS 27.
Apple’s CoreGraphics patch
The vulnerability, identified as CVE-2026-86950, is an out-of-bounds write: software writes beyond the memory area allocated for an operation. Apple says the updates address the flaw with improved bounds checking. Meta Product Security is credited with reporting it.
What Apple says about possible exploitation
Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27. Its wording describes possible exploitation; it does not state that an attack succeeded.
The stated risk involves processing a maliciously crafted file, which may lead to arbitrary code execution. That is the potential impact Apple associates with this CoreGraphics flaw.
Which iPhone and iPad models are listed
Apple lists iPhone 11 and later as eligible for iOS 26.7.1. Its iPad list includes:
- iPad Pro 12.9-inch (3rd generation and later)
- iPad Pro 11-inch (1st generation and later)
- iPad Air (3rd generation and later)
- iPad (8th generation and later)
- iPad mini (5th generation and later)
How iOS 26.7.1 differs from iOS 27.0.1
The two updates serve different software lines and have different purposes. iOS 26.7.1 addresses the CoreGraphics security flaw; iOS 27.0.1 is a separate bug-fix release.
| Update | Software line | Main purpose |
| iOS 26.7.1 | iOS 26 | Security patch for the CoreGraphics flaw |
| iOS 27.0.1 | iOS 27 | Separate bug fixes |