Apple patches a critical vulnerability in iPhone likely exploited in sophisticated attacks.

- Apple has released a critical security update for iPhones to address a vulnerability.
- The vulnerability, CVE-2026-86950, allows attackers to exploit memory corruption in iOS.
- Users are advised to install iOS 26.7.1 and iPadOS 26.7.1 updates immediately.
- Attacks reportedly targeted specific individuals, but no widespread campaign is indicated.
Apple has released a security update to address a critical vulnerability in iPhones, following indications that it may have already been exploited in a sophisticated attack targeting specific individuals.
The vulnerability, identified as CVE-2026-86950, affects the CoreGraphics framework responsible for processing visual content within the iOS system. A specially crafted malicious file can exploit this vulnerability to cause memory corruption, granting the attacker access to the device.
Apple fixed the vulnerability in the iOS 26.7.1 and iPadOS 26.7.1 updates released on September 28. The company advised users to install the update immediately to reduce the risk of exploitation.
How Does the Attack Work?
The vulnerability allows for an out-of-bounds write, which could lead to the execution of code specified by the attacker. However, no confirmed information exists regarding how the malicious file reaches victims, nor whether the attack requires user interaction. There is also no evidence suggesting that it is a Zero-Click attack.
What Has Apple Not Disclosed?
Apple has not clarified the type of file used in the attacks or whether the vulnerability is part of a larger exploitation chain. However, the company confirmed that the attacks targeted specific individuals, for whom the Lockdown Mode was designed to protect against advanced threats.
The product security team at Meta reported the vulnerability, but there is no evidence linking the attack to WhatsApp or Instagram services.
What Should iPhone Users Do?
- Install the iOS 26.7.1 update immediately if the device runs on versions of the iOS 26 series.
- Update older devices to the latest available security version.
- Be aware that the vulnerability has also been fixed on Mac devices, but the exploitation specifically targeted iPhone users.
No indications suggest a widespread campaign targeting ordinary users, but Apple believes the vulnerability has already been exploited, while the method of how the malicious file reached victims remains unknown.
To follow the news in Arabic


