Cybersecurity

iOS 26.7.1 patches a flaw that lets one rigged file run code on your iPhone

Adrian Kessler
Add us on Google

Apple has shipped iOS 26.7.1 to close a hole in CoreGraphics, the part of the system that draws images and opens PDFs, that let a single rigged file run an attacker’s code on an iPhone or iPad. The company says the flaw may already have been used against specific people. If your phone still runs iOS 26 instead of iOS 27, this is the update to install today.

The risk sits in something every phone does constantly without asking you. Photos, PDFs, previews in a chat, attachments in an email: all of them pass through CoreGraphics before they appear on screen. A flaw at that level means the victim does not have to install anything suspicious. Opening, or simply displaying, a booby-trapped file can be enough to hand over control.

Apple describes the bug as an out-of-bounds write, a programming error that lets data spill past the memory it was meant to fill and overwrite code the attacker wants to replace. The fix, in Apple’s words, adds improved bounds checking. The company says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

The flaw was reported to Apple by Meta’s product security team, which also protects WhatsApp, Instagram and Facebook Messenger, three apps that handle huge volumes of images and files every day. Neither company has said who was targeted, how many people were hit, or who was behind the attack, as TechCrunch reported.

Apple has used that same phrase, an extremely sophisticated attack against specific targeted individuals, in past cases tied to commercial spyware aimed at journalists, activists and officials rather than mass infections. For most iPhone owners the realistic danger is lower. The catch is that once a patch is public, researchers and criminals can study what changed and try to rebuild the exploit, so unpatched phones become easier targets over the following weeks.

There are gaps the update does not close. Apple’s advisory lists iPhone 11 and later, so owners of older models that cannot run iOS 26 get no fix from this release. None of the reports so far mention a patch for Macs on versions older than Sequoia. And people who face real targeting risk need more than one update: Apple’s Lockdown Mode, which switches off many file previews and attachment types, exists for exactly this kind of attack.

iOS 27 is not affected, which makes the choice simpler. It runs on the same phones as iOS 26, from the iPhone 11 onwards, so every device covered by this patch could also take the full upgrade. Many owners hold back from a major release for a few weeks to avoid early bugs or battery complaints; this fix lets them stay put without staying exposed. A separate iMessage flaw that needed no tap at all, found by the Belgian firm ironPeak, was already fixed in iOS 27 earlier this month, according to TechCrunch.

The patches cover more than phones. Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, alongside macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 for Macs. On iPad, the fix reaches the iPad Pro 12.9-inch from the third generation, the iPad Pro 11-inch from the first, the iPad Air from the third, the standard iPad from the eighth and the iPad mini from the fifth. The update is available worldwide through Settings, then General, then Software Update, and on a Mac through System Settings.

The flaw carries the identifier CVE-2026-86950. Apple has not said whether more details will follow, and it rarely publishes them for attacks it is still investigating. The only defense it offers is the one already sitting in the Software Update screen.

Tags: , , , , ,

Add us on Google

Discussion

There are 0 comments.