2 min read

Apple Patches Zero-Day Potentially Used in Targeted iPhone Attacks

The CoreGraphics flaw may enable arbitrary code execution through a malicious file, while no public evidence links it to confirmed cryptocurrency theft.

An iPhone rests beside a dimly lit wooden table / TokenPost.ai
An iPhone rests beside a dimly lit wooden table / TokenPost.ai

Apple patched a CoreGraphics vulnerability that may have been exploited against targeted iPhone users, but no public technical evidence confirms the flaw was used in attacks involving sensitive crypto-wallet data.

The company released iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28 to address CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics. Processing a maliciously crafted file could allow arbitrary code execution, giving an attacker a potential path to data accessible on the device.

Apple fixed the issue through improved bounds checking and credited Meta Product Security with reporting it. The company said the flaw may have been exploited in “an extremely sophisticated attack against specific targeted individuals” running iOS versions before iOS 27.

The vulnerability affects iPhone 11 and later models. Supported iPads include the iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later.

The Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities database on Sept. 29. The listing identifies the flaw as actively exploited but does not establish that cryptocurrency was stolen through it.

A separate security warning connected recent iOS exploitation activity with attacks targeting sensitive crypto-wallet data. No public technical evidence confirms that CVE-2026-86950 was used in that activity, and the connection does not establish confirmed cryptocurrency theft linked to the Apple patch.

Apple has not identified the attackers or victims, disclosed the number of compromised devices, described the malicious file or reported cryptocurrency losses. Its advisory also does not say that wallet applications, private keys or seed phrases were accessed.

An earlier warning about pre-iOS 27 software and crypto-wallet security covered broader risks affecting users of older Apple software. The latest step for affected devices is to install iOS 26.7.1, iPadOS 26.7.1 or a later available update.

Loading…