Skip to content

iOS 26.7.1 Fixes Vulnerability Used in Targeted Attacks

iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 address a major vulnerability that Apple believes was used against a small number of people.



Apple’s security support pages say there was a CoreGraphics out-of-bounds write issue that could be exploited with a maliciously crafted file, allowing for arbitrary code execution. It has been fixed with improved bounds checking.

Apple says the flaw was exploited in an “extremely sophisticated attack” on targeted individuals running older versions of iOS. Apple’s latest operating systems don’t appear to be affected, and the iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 updates that came out today have no published CVE entries.

While the attack wasn’t widespread, if you’re still running a version of iOS 26, iPadOS 26, macOS Tahoe, or macOS Sequoia, you should install the new updates as soon as possible. Now that the vulnerability is public, it could be further exploited against users who aren’t protected.

Related Roundups: iOS 26, iPadOS 26
Related Forum: iOS 26

This article, “iOS 26.7.1 Fixes Vulnerability Used in Targeted Attacks” first appeared on MacRumors.com

Discuss this article in our forums