An image or a document that an attacker controls can become a way in, and Apple says it holds evidence the approach has already been tested on real people.
Fixes went out on September 28 for a memory-safety defect catalogued as CVE-2026-86950. The weak spot sits in CoreGraphics, the drawing framework behind images and documents, where code could write beyond the end of a buffer. Apple closed it by tightening the bounds check.
Meta’s security team is credited with the report. Apple describes the victims as a narrow set of particular individuals singled out by a highly advanced operation rather than a broad campaign, and its account places the attempts before the arrival of iOS 27. No victim tally, success count or timeline has been released.
Phone users get the fix through iOS 26.7.1 and iPadOS 26.7.1, starting with iPhone 11 and later. Macs get it through macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Owners of iOS 18 hardware were left out, since that branch has stayed at 18.7.10 since August.
The same day brought four other builds, iOS 27.0.1, macOS Golden Gate 27.0.1, watchOS 27.0.1 and visionOS 27.0.1, none of which carry published CVEs. Golden Gate ships as 26A434, runs about 3.3 GB and does not shift the mBoot firmware version; its enterprise notes mention a lock-screen repair for Platform Single Sign-On.
Why the disclosure carries weight comes down to portability. Anything that renders a file it was handed becomes a candidate delivery route, and Apple’s own write-up gives another researcher enough to rebuild the trigger. A dyld memory corruption bug drew similar wording from the company in February.