Apple has pushed out an urgent round of security updates for people who haven’t moved to its latest software yet. iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 all close a vulnerability that Apple says was actively exploited against a small number of targeted individuals.
The flaw sits in CoreGraphics, the framework Apple’s operating systems rely on to render graphics. According to Apple, it was an out-of-bounds write issue that could be triggered by a maliciously crafted file, potentially allowing an attacker to run arbitrary code on the device. The fix comes in the form of improved bounds checking. In plain terms, opening the wrong file on an unpatched iPhone, iPad or Mac could have handed control of the device to someone else.
Apple describes the attack as highly sophisticated and aimed at specific people running older versions of iOS, rather than a broad campaign affecting the general public. That’s a familiar pattern for this kind of disclosure, and it usually points to well-resourced attackers going after carefully chosen targets. The company hasn’t shared who was targeted or who was behind it.
Anyone already on Apple’s newest software appears to be in the clear. iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 arrived on the same day, and none of them lists a related security entry, which suggests the current generation isn’t affected by this particular bug.
That still leaves a large group of users exposed. When iOS 27 launched earlier this month, Apple continued offering iOS 26 updates as the default option in Software Update, with iOS 27 available as an optional upgrade. Plenty of people choose to hold back on major releases until early bugs are ironed out, and this update exists specifically to protect them. The iOS 26.7 release that accompanied iOS 27 already carried more than 80 security fixes, 75 of which overlapped with the new operating system.
The main reason not to delay is that the vulnerability is now public. Once a flaw has been disclosed, the window for wider exploitation opens, and attackers who weren’t involved in the original campaign may try to take advantage of devices that haven’t been patched.
If you’re still using iOS 26, iPadOS 26, macOS Tahoe or macOS Sequoia, the update is worth installing now through Settings on iPhone and iPad, or System Settings on Mac. Staying on an older version is a reasonable choice for stability, but only if the security patches keep coming and actually get installed.
