Apple has released security updates fixing a flaw in CoreGraphics, the component behind how iPhones, iPads, and Macs render images and documents, after confirming it had already been used against real people. The bug, tracked as CVE-2026-86950, is an out-of-bounds write that lets a maliciously crafted file trigger code execution on the device that opens it. Apple's advisory says it is "aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals" running versions of iOS before iOS 27 — the kind of language Apple reserves for spyware-grade attacks, not everyday cybercrime.
The fix landed 28 September in iOS and iPadOS 26.7.1 (iPhone 11 and later, iPad Pro 3rd generation and later), macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Meta's Product Security team reported the flaw to Apple. Apple hasn't said how many people were targeted or when the exploitation first began, which is typical for these disclosures — the attacker's toolkit is usually still being investigated when the patch ships.
What this means for your business
"Targeted individuals" attacks are usually aimed narrowly at first — executives, journalists, activists, people handling sensitive deals — but the same flaw becomes fair game for wider abuse once it's public and unpatched devices are still out there. Treat this as a same-week update, not a someday one: push the update to every company iPhone, iPad, and Mac, including personal devices that touch work email or files. If anyone on your team handles sensitive negotiations, legal matters, or executive communications, they're exactly the profile this kind of attack targets first — worth a direct nudge rather than assuming they'll see the update badge on their own. If your business manages a device fleet through an MDM tool, this is a good moment to confirm update compliance is actually being enforced, not just offered.