iOS 26.7.1 Fixes CoreGraphics Flaw: Who Should Update

3 min read

Switching to Mac is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

September 29, 2026. Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28 to fix a CoreGraphics security flaw. Apple says it may have been used to target specific people. If your iPhone or iPad is staying on version 26, install the update.

What Happened

Apple’s security advisory names the flaw CVE-2026-86950. It’s an out-of-bounds write in CoreGraphics, which handles graphics. A crafted file could let an attacker run code on the device. In plain language, the flaw allowed data to be written beyond its intended memory boundary. Apple added checks to keep writes within that boundary.

Apple says the flaw may have been exploited in an extremely sophisticated attack against specific individuals using iOS versions before iOS 27. That doesn’t mean attacks are widespread or that every harmful file can trigger the flaw. Apple credits Meta Product Security in the advisory.

Apple’s September 28, 2026 advisory describes the CoreGraphics bounds-checking fix for CVE-2026-86950.

Who This Affects

iOS: Supported iPhones

Apple lists iPhone 11 or later as eligible for iOS 26.7.1 in its security advisory. If your iPhone is still on iOS 26, install this update.

iPadOS: Supported iPads

Apple lists these models as eligible for iPadOS 26.7.1 in the same advisory:

  • iPad Pro 12.9-inch (3rd generation) or later
  • iPad Pro 11-inch (1st generation) or later
  • iPad Air (3rd generation) or later
  • iPad (8th generation) or later
  • iPad mini (5th generation) or later

Unsure which iPad you have? Open Settings > General > About and check Model Name.

How It Stacks Up

iOS 26.7.1 and iPadOS 26.7.1 bring the fix to eligible devices on version 26. Moving to iOS 27 is a separate choice. Apple’s warning mentions iOS versions before iOS 27. Its 26.7.1 advisory doesn’t compare speed, battery life, or overall safety.

PlatformWhat Apple’s advisory says
iOS 26.7.1 and iPadOS 26.7.1These September 28, 2026 updates fix CVE-2026-86950 with better bounds checking. Source: Apple
Earlier iOS 26 and iPadOS 26 releasesApple provides 26.7.1 as the fix for eligible devices staying on version 26. Source: Apple
macOS Tahoe 26.7.1 and Sequoia 15.8.1Apple lists corresponding CoreGraphics fixes for both Mac branches, including Sequoia 15.8.1. Install the update appropriate for your Mac’s branch.
Google Pixel, Samsung Galaxy, and WindowsThis Apple advisory doesn’t compare Android or Windows security fixes with this update.

The cited material has no speed or battery life test results. Treat claims about either one as unverified until tests or further documents back them up.

What to Do Next

On an eligible iPhone running iOS 26, open Settings > General > Software Update. Install iOS 26.7.1 if it appears. Follow the same path on an eligible iPad running iPadOS 26 to install iPadOS 26.7.1. If you already run iOS 27.0.1 or iPadOS 27.0.1, you are on the newer branch; do not look for 26.7.1 or try to downgrade. Check Apple’s security releases page for the current version for your device.

Our Take

Verdict: Update if you’re staying on version 26. This flaw could have a serious impact. Apple has received a report that it may have been used against specific people. That’s reason enough to install the fix. The report doesn’t show a widespread attack or support a comparison with Android or Windows fixes.