Apple issues emergency update for millions of iPhones, iPads, and Macs
Apple issued an emergency security update, including iOS 26.7.1, to fix a zero-day vulnerability affecting millions of iPhones, iPads, and Macs. The flaw, identified as CVE-2026-86950, exists in the CoreGraphics engine used for interface and screen processing. A malicious file can trigger the bug, allowing attackers to run arbitrary code on devices. Apple confirmed the vulnerability was used in sophisticated attacks targeting specific individuals. Users on iOS 26, iPadOS 26, and macOS 26 are urged to update immediately to prevent device hijacking.
Listen to Live Briefing
Real-time synthesized voice briefing Β· Live Feeds Desk
- β Apple released iOS 26.7.1 to patch a zero-day vulnerability.
- β The flaw affects iPhones, iPads, and Macs running iOS 26, iPadOS 26, and macOS 26.
- β The vulnerability allows attackers to run code on a device via a malicious file.
- β Apple stated the bug was used to attack specific targeted individuals.
What changed
Meta's security team identified the specific flaw as CVE-2026-86950 located in the CoreGraphics engine.
Live updates
-
Apple releases emergency patch for iOS 26 zero-day vulnerability
Apple issued an emergency security update, including iOS 26.7.1, to fix a zero-day vulnerability affecting millions of iPhones, iPads, and Macs. The flaw, identified as CVE-2026-86950, exists in the CoreGraphics engine used for interface and screen processing. A malicious file can trigger the bug, allowing attackers to run arbitrary code on devices. Apple confirmed the vulnerability was used in sophisticated attacks targeting specific individuals. Users on iOS 26, iPadOS 26, and macOS 26 are urged to update immediately to prevent device hijacking.
Why it matters
The vulnerability was discovered by Meta's security team. It is described as a zero-click flaw, meaning it can be triggered without user interaction. This patch specifically targets users who have not yet upgraded to iOS 27.
What is confirmed
- Apple released iOS 26.7.1 to patch a zero-day vulnerability.
- The flaw affects iPhones, iPads, and Macs running iOS 26, iPadOS 26, and macOS 26.
- The vulnerability allows attackers to run code on a device via a malicious file.
- Apple stated the bug was used to attack specific targeted individuals.
- The vulnerability is located in the CoreGraphics engine.
Still unconfirmed
- The attack is described as an extremely sophisticated attack plaguing devices.
- The flaw is a zero-click vulnerability.
What to watch next
- Reports on the number of devices successfully compromised by the exploit
- Official confirmation of the specific nature of the targeted attacks
- Further updates for macOS and iPadOS version numbers
confidence 95%Sources used for this update (18)
- Forbes β iOS 26.7.1βUpdate Now Warning Issued To iPhone Users
- darkreading.com β Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
- CNET β Still on iOS 26? You Need to Download iOS 26.7.1 Now for This Zero-Day Patch
- Tom's Guide β Apple issues emergency update for millions of iPhones, iPads, and Macs β update your devices now
- malwarebytes.com β Update your iPhone, iPad, or Mac: Flaw could run attackersβ code
- techcrunch.com β Still running iOS 26? Update your iPhones, iPads, and Macs ...
- www.malwarebytes.com β Update your iPhone, iPad, or Mac: Flaw could run attackers ...
- www.dailymail.com β Apple issues warning to iPhone users over 'sophisticated attack' hijacking devices: Act NOW
- www.computerworld.com β Apple issues urgent iOS patch as it navigates the spyware arms race β Computerworld
- www.tomsguide.com β Apple issues emergency update for millions of iPhones, iPads, and Macs β update your devices now
- tech.yahoo.com β Security researchers discover fake ChatGPT ads that trick you into downloading malware
- www.tomsguide.com β Amazon expands FTC settlement, pays Prime members up to $200
Community Sentiment: How do you assess this situation?
Voice your perspective Β· Real-time aggregated sentiment from the Live Feeds community