Apple has pushed out an emergency patch after confirming that a severe graphics flaw may already have been weaponized against iPhone and iPad users.
The Cupertino company, 48, warned that the vulnerability tracked as CVE-2026-86950 sits inside CoreGraphics, the engine that renders 2D images across its mobile platforms. A corrupted file processed by an unpatched device can trigger arbitrary code execution, handing attackers control of the system. Meta Product Security discovered and reported the bug, which Apple said was fixed through improved bounds checking.
“Processing a maliciously crafted file may lead to arbitrary code execution,” the company confirmed in its security bulletin.
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
The emergency updates iOS 26.7.1 and iPadOS 26.7.1 cover the iPhone 11 and later, plus several tablet lines including the iPad Pro 12.9-inch 3rd generation and later, the iPad Air 3rd generation and later, the iPad 8th generation and later, and the iPad mini 5th generation and later. Users install the patch through Settings, then General, then Software Update.

Those already on iOS 27, released with a redesigned Liquid Glass interface and expanded Apple Intelligence features, are not vulnerable to this specific exploit. The new operating system also introduces Impersonation Risk Detection, an on-device tool that assesses scam risk during high-stakes actions like password changes. When a supported app requests a check, the system returns a rating of unknown, medium, or high without transmitting personal data to Apple servers. An app flagged as high-risk can delay payments, display warnings, or demand identity verification before proceeding.
The CoreGraphics flaw represents the latest in a pattern of targeted attacks against Apple users through image-handling pathways. Security researchers have long identified graphics parsers as attractive attack surfaces because they process complex file formats with extensive code bases. Meta’s security team, which maintains its own vulnerability research program separate from its consumer platforms, reported this particular bug through coordinated disclosure.
Apple added: “An out-of-bounds write issue was addressed with improved bounds checking.”

The company did not specify which targeted individuals may have been hit, how many were affected, or what region they were in, consistent with its typical practice for narrowly focused espionage-style campaigns. The phrase “extremely sophisticated attack” in Apple’s own statement signals an operation with significant resources behind it, rather than mass-market criminal tooling.
Users who cannot upgrade to iOS 27 remain dependent on these periodic emergency patches for older supported versions. The iPhone 11, released in 2019, is the oldest phone eligible for this fix, meaning models from the iPhone XS generation and earlier no longer receive security updates. Apple’s support window for mobile devices typically extends five to six years from release.
The Impersonation Risk Detection feature in iOS 27 addresses a different threat vector entirely: social engineering scams where criminals manipulate victims into disabling protections or revealing credentials directly. By keeping the analysis on-device, Apple attempts to balance fraud prevention with privacy commitments that have become central to its marketing.
Users on affected devices should verify their update status immediately, as the window between patch release and exploitation of known flaws by broader attacker groups often narrows to days or hours.
Apple is expected to continue rolling out iOS 27 features to additional device models through the coming weeks.

