iOS 26.7.1 and iPadOS 26.7.1 shipped on 28 September with a single fix. A malicious file can lead to code execution, and Apple is aware of a report that the hole may have been exploited in an extremely sophisticated attack against specific individuals.
- CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the system's graphics library.
- Apple is aware of a report of exploitation against specific individuals on versions of iOS before iOS 27.
- It was found by Meta Product Security. The update covers iPhone 11 and later and the matching iPads.
An update with one fix is the clearest signal Apple knows how to send. When they ship a version for a single line, the line matters.
Apple's wording is worth reading slowly. "May have been exploited". "Specific targeted individuals". This is not a mass campaign against every phone. If the report is right, it is a tool that someone has been pointing at particular people.
If you are not one of the specific people the attack was aimed at, you probably were not a target. But once it is described, a hole stops belonging only to those who used it first.
The bulletin is for iOS 26, and the attack Apple knows about is on versions before iOS 27. If your phone is still on 26: Settings, General, Software Update. Tonight, while it charges.