Apple released an emergency security update on September 29, 2026, fixing a flaw that has already been used in real attacks against iPhone users. If you have not moved to iOS 27 yet, this one is not optional. Here is exactly who needs it and how to install it.
Quick Answer
- Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 on September 29, 2026
- The fix addresses CVE-2026-86950, a flaw Apple says may have already been used in a “highly targeted attack”
- This affects devices running any iOS version before iOS 27, not iPhones already updated to iOS 27
- Just opening a malicious file (like an image or PDF) could let an attacker run their own code on your device
- Install this update immediately if you have not yet moved to iOS 27
Who Actually Needs This Update
This is the part that trips people up. If your iPhone is already running iOS 27, you do not need this specific patch, since the vulnerability affects versions before iOS 27. This update is for:
- iPhones and iPads still running iOS 26 or earlier, whether by choice or because the device is not eligible for iOS 27
- Macs running macOS Tahoe or macOS Sequoia
If you are not sure which iOS version you are on, check under Settings > General > About.
What the Flaw Actually Does
The bug lives in CoreGraphics, a core piece of Apple’s software used across iPhones, iPads, and Macs to display and process images, PDFs, and other visual content. It is what is called an out-of-bounds write, meaning a specially crafted file can trick the system into writing data outside where it is supposed to go. In the worst case, that lets an attacker run their own code on your device.
Apple says it is aware of a report that this flaw may have been exploited in what it called an “extremely sophisticated attack” against specific individuals, all running versions of iOS before iOS 27. In plain terms: someone, somewhere, has already used this to target real people, and Apple has now patched it. Because the flaw is now public, security researchers warn that other attackers could try to use it too, even though the original attack was narrowly targeted.
Which Devices Are Covered
| Update | Available For |
|---|---|
| iOS 26.7.1 / iPadOS 26.7.1 | iPhone 11 and later, iPad Pro 12.9-inch (3rd gen) and later, iPad Pro 11-inch (1st gen) and later, iPad Air (3rd gen) and later, iPad (8th gen) and later, iPad mini (5th gen) and later |
| macOS Tahoe 26.7.1 | Macs running macOS Tahoe |
| macOS Sequoia 15.8.1 | Macs running macOS Sequoia |
How to Update Your iPhone or iPad
- Go to Settings
- Tap General
- Tap Software Update
- If iOS 26.7.1 is offered, tap Update Now and follow the prompts
While you’re there, it is worth turning on Automatic Updates on the same screen, so you get security fixes like this one as soon as they’re released.
How to Update Your Mac
- Click the Apple menu in the top-left corner
- Open System Settings
- Click General, then Software Update
- If an update is available, click Update Now and follow the prompts
- Keep your Mac plugged in and connected to the internet until it finishes
Should I Just Update to iOS 27 Instead
If your device is eligible for iOS 27, updating straight to it is a reasonable option too, since it includes this same security fix along with everything else iOS 27 introduced, including the new Siri AI. We covered what’s actually new in our full iOS 27 guide. The one thing to know: if your device cannot run iOS 27, or you have deliberately stayed on iOS 26 for compatibility reasons, iOS 26.7.1 is the update you need instead, and it will continue getting security patches like this one going forward.
Frequently Asked Questions
Do I need iOS 26.7.1 if I already have iOS 27?
No. This specific vulnerability affects versions of iOS before iOS 27. If you are already on iOS 27, you are not affected by this particular flaw.
Has this security flaw actually been used against real people?
Apple says it is aware of a report suggesting it may have been used in a highly targeted, sophisticated attack against specific individuals. It was not a broad, widespread attack.
What could happen if my device was affected?
Opening a malicious file, such as a crafted image or PDF, could let an attacker run their own code on your device.
How urgent is this update?
Very. Since the flaw is now publicly disclosed, security researchers warn other attackers could attempt to exploit it, even though the original reported attack was narrow.
Does this affect Macs too?
Yes. Apple released matching security updates for macOS Tahoe and macOS Sequoia.
My iPhone isn’t eligible for iOS 27. Am I still protected?
Yes, as long as you install iOS 26.7.1, which contains this same security fix for devices still on the iOS 26 track.
How do I check which iOS version I’m running?
Go to Settings > General > About, and check the Software Version listed there.