The Latest iOS 26 Update Blocks A Serious Security Threat For iPhone Users

Add SlashGear on Google:
Google Discover

Following the global rollout of Apple's 2026/2027 generation of operating systems (known as version 27) for iOS, iPadOS, watchOS, and macOS, Apple has been busy with patches and bug fixes. Apple had to scramble to address a Face ID bug affecting its latest iPhone 18 Pro and iPhone 18 Pro Max models, causing Face ID to fail and forcing a hard restart. Apple also had to update its watchOS platform to watchOS 27.0.1 to address a bug forcing some Watch Series 12 and Ultra 4 models to randomly restart. Apple has since rolled out iOS 27.0.1 and iPadOS 27.0.1 to address a number of other smaller fixes, as well as macOS 27.0.1, which brings security and performance fixes.

While most of these incremental updates usually bring the standard fare of early bug and performance fixes, a notable security vulnerability affects the previous version of some of these operating systems. Meta Product Security discovered a security flaw in iOS 26 that's related to Apple's Core Graphics framework, which has now been published as CVE-2026-86950. This is hot on the heels of a zero-click vulnerability affecting iMessage, published and patched as CVE-2026-86869.

For iPhones not running iOS 27, or for older iPhones that aren't going to get iOS 27, it's highly recommended to update to iOS 26.7.1 to get the latest security fix for CVE-2026-86950. Apple has also released macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, as well as iPadOS 26.7.1, to fix this security issue.

What is Core Graphics and how to update your devices

According to Apple's security page for iOS and iPadOS 26.7.1, the security content addresses: "Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Arbitrary code execution allows attackers to run injected code by exploiting a known flaw – in this case, a component for Apple's Core Graphics engine.

Core Graphics is a low-level rendering framework for 2D rendering, path-based drawing, colors, fonts, and PDF and image manipulation. This graphics framework is a major part of iOS, iPadOS, and macOS, making it a significant attack surface for an attacker with an exploit. The Cybersecurity & Infrastructure Security Agency (CISA) also added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) Catalog, which requires Federal Civilian Executive Branch (FCEB) agencies to address vulnerabilities within a certain timeline.

To check for updates on iOS and iPadOS, navigate to Settings and follow General > Software Update. On Macs, click the Apple menu in the upper left-hand corner, then go to System Settings > General > Software Update. You can also use Spotlight or Siri AI to open the Software Update feature. If your devices are already running version 27 of their respective operating systems, you're already protected against this particular threat. If you haven't already, here's how you can upgrade to iOS 27 and learn about the biggest changes.

Recommended