Apple has released an urgent security update for iPhones, iPads and Macs running its previous-generation operating systems after warning that a vulnerability in its graphics software may have already been exploited in targeted attacks.

The vulnerability, identified as CVE-2026-86950, affects the CoreGraphics engine used to process graphics and visual content across Apple devices. Apple said processing a maliciously crafted file could allow an attacker to execute arbitrary code on an affected device.
Apple said it was aware of a report that the vulnerability had been exploited in an “extremely sophisticated attack” against specific targeted individuals using versions of iOS before iOS 27. The company did not disclose how many people had been affected or identify the attackers.
Interestingly, the vulnerability was discovered by Meta’s product security team. Apple addressed the flaw through iOS 26.7.1 and iPadOS 26.7.1, released on September 28, alongside security updates for compatible Mac operating systems.
The update is particularly relevant to users who have remained on iOS 26 after Apple released iOS 27 earlier this month. Apple said almost four in five iPhone users were still running iOS 26 when the vulnerability was disclosed.
Devices running iOS 27, iPadOS 27 and macOS 27 were not affected by this particular vulnerability, according to Apple.
The flaw is significant because CoreGraphics sits within the operating system’s graphics infrastructure and processes content received from files and other sources. A successful exploit could potentially give an attacker access to other parts of a device, although Apple has not disclosed the extent of any attacks involving the vulnerability.
The latest patch follows another serious Apple security issue fixed earlier this month. That vulnerability, tracked as CVE-2026-86869, was described by cybersecurity researchers as a zero-click flaw that could potentially be triggered through a maliciously crafted iMessage without requiring the victim to interact with it.
Apple fixed that vulnerability with the release of iOS 27, iPadOS 27 and macOS 27.
The latest disclosure highlights the security risks faced by users who delay operating system updates, particularly when vulnerabilities are known to have been exploited.
Apple has not said whether the newly patched CoreGraphics vulnerability was used by commercial spyware companies, cybercriminals or another type of attacker.
Users running iOS 26 can install the latest security update through the Software Update section in their device settings. Apple recommends keeping supported devices updated as security patches become available.
Stay ahead of the Stories shaping our world. Subscribe to Impact Newswire and join our
WhatsApp Channel for updates on global tech, business, and innovation—all in one place.
Dive deeper into the future with the Cause Effect 4.0 Podcast, where we explore the ideas, trends, and technologies driving the global AI conversation.
Got a story to share? Contact Us to reach a global audience with Impact Newswire.
Emmanuel Abara Benson is a business journalist and editor covering artificial intelligence, global markets, and emerging technology.
He has previously worked with Business Insider Africa and Nairametrics, reporting on finance, startups, and innovation.
His work focuses on AI, digital economy, and global tech trends.
Discover more from Impact Newswire
Subscribe to get the latest posts sent to your email.



