Science & Technology

Apple fixes a serious vulnerability in iPhone likely exploited in advanced attacks.

Story Highlights
  • Apple released a security update to fix a serious iPhone vulnerability.
  • The flaw, CVE-2026-86950, affects the CoreGraphics framework in iOS.
  • Attackers may have exploited the vulnerability in targeted attacks on specific individuals.
  • Users are urged to install the iOS 26.7.1 update to mitigate risks.

Apple Releases Security Update for iPhone Vulnerability

Apple has issued a security update to address a serious vulnerability in iPhones. The company indicated that this flaw may have already been exploited in a sophisticated attack targeting specific individuals.

Details of the Vulnerability

The vulnerability, identified as CVE-2026-86950, affects the CoreGraphics framework responsible for processing visual content within the iOS system. A specially crafted malicious file can exploit this flaw, causing memory corruption that allows attackers to gain access to the device.

Apple fixed the vulnerability in the iOS 26.7.1 and iPadOS 26.7.1 updates released on September 28. The company urged users to install the update immediately to reduce the risk of exploitation.

How Does the Attack Work?

This vulnerability allows for an out-of-bounds write, which could lead to the execution of code specified by the attacker. However, there is currently no confirmed information on how the malicious file reaches victims or whether the attack requires user interaction. Additionally, there is no evidence to suggest that this is a Zero-Click attack.

What Has Apple Not Disclosed?

Apple has not clarified the type of file used in the attacks or whether the vulnerability is part of a larger exploitation chain. However, the company confirmed that the attacks targeted specific individuals, which is the type of threat that Lockdown Mode was designed to protect against.

The Product Security team at Meta reported the vulnerability, but there is no evidence linking the attack to WhatsApp or Instagram services.

What Should iPhone Users Do?

  • Install the iOS 26.7.1 update immediately if the device runs on versions of the iOS 26 series.
  • Update older devices to the latest available security version.
  • Be aware that the vulnerability has also been fixed on Mac devices, but the exploitation specifically targeted iPhone users.

There are no indications of a widespread campaign targeting ordinary users. However, Apple believes that the vulnerability has already been exploited, while the method of how the malicious file was delivered remains unknown.

The post Apple Addresses Serious iPhone Vulnerability Likely Exploited in Sophisticated Attacks appeared first on Yemen TV.

To follow the news in Arabic

Via
Yemen TV

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Developed by ​Infragate Solutions LTD