MalwareTips News Apple patches actively targeted CoreGraphics flaw on iPhone, iPad and Mac

Security News
0 Replies 66 Views

Have you installed the latest security update on your Apple devices?

  • Yes, on all of them

    Votes: 1 100.0%
  • On some, but not all

    Votes: 0 0.0%
  • Not yet

    Votes: 0 0.0%
  • I am not sure

    Votes: 0 0.0%
  • I do not use Apple devices

    Votes: 0 0.0%

  • Total voters
    1

News Now

Happening Now
Verified
MalwareTips-news-135.jpg

Image: Malwarebytes Labs

Apple has released security updates for supported iPhones, iPads and Macs after reports that a file-processing flaw may have been used against selected iPhone users. Malwarebytes Labs says installing the latest update offered through Software Update closes the weakness.


Updates now available​

The fixes are included in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Availability depends on the device model and operating system currently installed.

  • On an iPhone or iPad, open Settings > General > Software Update, install the update offered and enable Automatic Updates from the same screen.
  • On a Mac, open the Apple menu > System Settings > General > Software Update, then select Update Now if an update is available.
  • Keep a Mac plugged in and connected to the internet while installation finishes; it may restart.

A malicious file could run code​

Tracked as CVE-2026-86950, the bug affects CoreGraphics, the Apple component that handles visual content such as images and PDF files across its operating systems and apps.

It is an out-of-bounds write, meaning software can write past the memory area assigned to it. Processing a specially crafted file could corrupt memory, crash the affected process or allow an attacker to run their own code.

Apple addressed the problem by improving bounds checking, which verifies that software stays within the correct memory limits.

Reported attacks were narrowly targeted​

Apple says it received a report that the flaw may have been exploited in an “extremely sophisticated attack” against specific people using iOS versions earlier than iOS 27. The available information does not indicate widespread exploitation.
 
Back
Top