iOS 26.7.1 fixes Core Graphics flaw CVE-2026-86950
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and Sequoia 15.8.1 to patch CVE-2026-86950, a Core Graphics flaw that allows arbitrary code execution via a maliciously crafted file. CISA added it to its Known Exploited Vulnerabilities catalog, and Apple says the issue may have been exploited in targeted attacks on iOS before version 27.
- CVE-2026-86950 in Core Graphics allows arbitrary code execution via a crafted file
- Apple is aware of exploitation in targeted attacks on iOS before version 27
- CISA added the flaw to its Known Exploited Vulnerabilities catalog
- Patches cover iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 and Sequoia 15.8.1
Read next
Software