iOS 26.7.1 Fixes an Exploited Zero-Day: Should You Update Your iPhone and Mac?

Apple has patched CVE-2026-86950, a CoreGraphics flaw it says may have been used in targeted attacks. Here’s which iPhones, iPads and Macs need iOS 26.7.1, macOS Tahoe 26.7.1 or Sequoia 15.8.1, and how to install it.

By Oscar Leiva

4–5 minutes
Illustration of a smartphone and laptop behind a glowing security shield as a damaged image file is patched

Last updated: October 1, 2026

The quick answer

Yes, update now if your iPhone, iPad or Mac is still on version 26 (or macOS Sequoia). Apple’s iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 fix a CoreGraphics bug that Apple says may have been exploited in targeted attacks. If you already run iOS 27 or macOS 27, current reports say you are not affected, but staying on the newest point release is still the safest choice.

What happened

On September 28, 2026, Apple released iOS 26.7.1 and iPadOS 26.7.1, a small update with a single security fix. The flaw, tracked as CVE-2026-86950, sits in CoreGraphics, the part of Apple’s software that draws and processes images, PDFs and other graphics.

Apple describes it as an out-of-bounds write, a type of memory bug where software writes data outside the space it is supposed to use. Help Net Security reports that a specially crafted file could use it to run an attacker’s code on the device. Apple fixed it with stricter bounds checking.

What makes this update urgent is Apple’s own warning. The company says it is aware of a report that the bug may have been used in an “extremely sophisticated attack against specific targeted individuals” on versions of iOS before iOS 27. That is the wording Apple typically uses for spyware-style campaigns aimed at a small number of people, not mass attacks.

According to Help Net Security and Security Affairs, the bug was reported by Meta’s product security team, and the same fix also shipped for Macs.

Which updates contain the fix

If you useInstall this version
iPhone on iOS 26iOS 26.7.1
iPad on iPadOS 26iPadOS 26.7.1
Mac on macOS TahoemacOS Tahoe 26.7.1
Mac on macOS SequoiamacOS Sequoia 15.8.1
iPhone, iPad or Mac on version 27Latest 27.x update (reports say 27.0.1 is not affected)

Apple lists the iOS and iPadOS fix for iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later).

What changes for you

You will not see new features after installing this update. Its only job is to close a security hole that someone has reportedly already used. Because the bug lives in a system component that handles images and documents, it could in principle be triggered by content you open or receive, which is why fixes like this matter even if you are careful about what you click.

The realistic risk for most people is low, since the reported attacks were narrowly targeted. But once a fix is public, details of the flaw tend to spread, and older unpatched devices become easier targets over time. Installing the update removes that risk entirely.

How to update

  1. Back up first if you have not done so recently, using iCloud or your computer.
  2. On iPhone or iPad: open Settings > General > Software Update and install iOS or iPadOS 26.7.1 (or the latest version 27 update if you have chosen to move to iOS 27).
  3. On a Mac: open System Settings > General > Software Update and install macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, depending on which version you run.
  4. Restart when prompted. The fix is not active until the device reboots.
  5. Turn on automatic updates in the same screen so future security fixes install without you having to remember.

If you are at higher risk, for example a journalist, activist, lawyer or public official, consider also turning on Lockdown Mode under Settings > Privacy & Security. It limits some features in exchange for stronger protection against targeted spyware.

Who it affects and who it doesn’t

  • Affects: iPhones and iPads still on iOS or iPadOS 26, and Macs on macOS Tahoe 26 or macOS Sequoia 15 that have not installed the new updates.
  • Most urgent for: people who could be targets of surveillance, given Apple’s note about targeted attacks.
  • Doesn’t appear to affect: devices already on iOS 27.0.1, iPadOS 27.0.1 or macOS 27.0.1, according to Help Net Security’s reading of Apple’s notes.

If you use a Mac with a Microsoft 365 work account, there is a separate change this month that may affect Apple Mail. See our guide to Microsoft’s October 2026 deadlines.

FAQ

Do I have to upgrade to iOS 27 to be safe?

No. Apple released iOS 26.7.1 specifically so people who stay on iOS 26 get the fix. Installing either the latest iOS 26 or the latest iOS 27 update protects you.

How do I know if my device was attacked?

Apple has not published signs to look for, and targeted attacks of this kind are designed to be hard to spot. If you believe you are being targeted, update immediately, enable Lockdown Mode and seek help from a digital security organization.

Is my older iPhone covered?

Apple’s iOS 26.7.1 notes list iPhone 11 and later. Devices that cannot run iOS 26 are not included in this advisory, so check Apple’s security updates page for your model.

Sources

About the author

Oscar Leiva

Oscar edits Knowloft’s guides from San Salvador, El Salvador, as part of Edén Studio, a creative and software studio. Each guide is built from official data and current local prices, cites its sources and is updated when costs or rules change. Read our editorial standards.

Leave a Reply

More guides

Discover more from Knowloft

Subscribe now to keep reading and get access to the full archive.

Continue reading