A vulnerable device does not need to run an unfamiliar app for this issue to matter. Apple’s September 28 security notes say that processing a maliciously crafted file can lead to arbitrary code execution in CoreGraphics, the system component that handles graphics content. Apple fixed the out-of-bounds write as CVE-2026-86950 and says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific people using iOS versions before iOS 27. That wording warrants urgent patching, but it does not identify the attacker, delivery method, number of victims, or a general campaign against every Apple user. Apple’s iOS and iPadOS advisory

The defender’s job is to identify devices still on the affected software branches, update them, and verify the running version. CISA added this CVE to its Known Exploited Vulnerabilities catalog on September 29, adding urgency without revealing the missing attack details. If a person has received an Apple threat notification or has credible evidence of targeting, handle that as a separate incident-response question. An operating-system update closes the known flaw; it cannot prove that an already compromised device is clean.

Which Updates Matter?

Apple published the following CoreGraphics fixes on September 28, 2026. Use the device’s current OS branch and Apple’s Software Update screen to select the applicable release; do not assume the same version number applies to every product.

Device and branchFix listed by AppleWhat to check
Supported iPhone or iPad on iOS/iPadOS 26iOS 26.7.1 or iPadOS 26.7.1The installed version is 26.7.1 or a later applicable update. Apple’s advisory lists iPhone 11 and later and specific supported iPad models.
Mac on macOS Tahoe 26macOS Tahoe 26.7.1The installed Tahoe version is 26.7.1 or later.
Mac on macOS Sequoia 15macOS Sequoia 15.8.1The installed Sequoia version is 15.8.1 or later.

Apple’s security releases index is the source of truth for releases added after this article. Apple describes reported exploitation on iOS before iOS 27; the presence of a corresponding macOS fix does not, by itself, establish observed exploitation against Macs. Likewise, a device on another OS branch should be checked against Apple’s current release guidance rather than being declared affected or safe from a version number alone.

Patch and Verify, by Owner

For an individual: On iPhone or iPad, open Settings → General → Software Update and install the available security update. On a Mac, use System Settings → General → Software Update. Keep the device powered and allow it to restart. Then return to the version screen: Settings → General → About on iPhone/iPad, or About This Mac on macOS. Compare the installed version with the table above and Apple’s current release index. These are Apple’s documented iPhone and iPad update path and Mac update path. A downloaded update or a successful MDM command is not enough evidence; confirm the version running after restart.

For an organization: Endpoint and mobile-device teams should inventory iPhones, iPads, and Macs by model, OS branch, and last check-in. Push the appropriate update through the existing device-management process, then use the next post-restart inventory to count devices below the fixed version. Investigate devices that are offline, unsupported, managed by another team, or repeatedly failing installation. Record a named owner and exception for each remaining device. If business software prevents an immediate update, limit that device’s access to sensitive workflows while the exception is resolved; that is an operational risk reduction, not a proven mitigation for this CoreGraphics bug.

Do not present “avoid suspicious attachments” as a reliable fix. Apple has not publicly described how the file reached targets or whether preview behavior was involved. Antivirus, MFA, and password changes do not repair an out-of-bounds write in the OS. The security update is the control that removes the documented vulnerability.

If You May Be a Target

Apple’s threat-notification guidance says a genuine notification can be checked by signing in directly at account.apple.com; the notification appears at the top of the account page. Apple says its alerts do not ask you to open an attachment, install a profile, or provide a password or verification code. If you receive one, involve your security team or a specialist support organization and preserve relevant messages, dates, and device details before making major changes. Do not infer from this CVE alone that a particular suspicious message used it.

For people at unusually high risk of targeted spyware, Apple offers Lockdown Mode. It restricts certain apps, websites, attachments, and connectivity features, so test whether the tradeoffs fit the person’s work. Apple recommends updating first, and the mode must be enabled separately on each iPhone, iPad, and Mac. Lockdown Mode is additional attack-surface reduction; Apple has not claimed it specifically blocks CVE-2026-86950 or substitutes for the patch.

If there is credible evidence of compromise, isolate the device from sensitive access under your incident-response process, preserve evidence, and seek specialist analysis. Do not use an absence of alerts or a completed update as proof that prior exploitation did not occur.

For the wider incident-response context of targeted mobile surveillance, see our Pegasus case analysis. That case does not establish who used CVE-2026-86950.

Sources