Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Apple updates fix CoreGraphics flaw possibly used in attacks

Published 29 September 2026

Apple has released security updates for iOS, iPadOS and macOS to fix a CoreGraphics vulnerability that the company says may have been exploited in an exceptionally sophisticated attack against specifically targeted people using iOS versions before iOS 27. Apple has not disclosed how many people were targeted, whether any attack succeeded or when exploitation may have occurred. The flaw is an out-of-bounds write, a memory-handling error that can occur when software writes beyond an allocated buffer. Apple’s security information says processing a maliciously crafted file could allow arbitrary code execution. The company says it addressed the issue with improved bounds checking. Apple lists the fix in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Meta Product Security reported the vulnerability, according to Apple’s attribution. The updates provide a fix for the listed operating-system versions; reports do not establish that every device or version is affected. The company’s notice describes possible exploitation, rather than confirming successful compromises or providing an incident count.

Now playing
0:00 / 0:00