Update your iPhone, iPad, or Mac: Flaw could run attackers’ code

Imported from official source

Cybersecurity Classified by Officially

Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27.

The fix is in iOS and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Check Software Update on each of your Apple devices and install the latest version offered.

The table below shows which relevant updates are available and links to Apple’s security information for each one.

To check if you’re using the latest software version, go to Settings > General > Software Update. You’ll see if an update is available and be guided through installing it.

Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.

To update macOS on any supported Mac, use Software Update:

  • Click the Apple menu in the upper-left corner of your screen.
  • Choose System Settings (or System Preferences on older versions).
  • Select General in the sidebar, then click Software Update on the right. On older macOS, look for Software Update directly.
  • Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, read Apple’s instructions.
  • Enter your administrator password if prompted, then let your Mac finish the update. It may need to restart.
  • Make sure your Mac stays plugged in and connected to the internet until the update is done.
  • The bug, CVE-2026-86950, affects CoreGraphics, an Apple framework used throughout its operating systems and apps to display and process visual content such as images and PDFs.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code

    Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Malwarebytes — imported from official source
    Official source
    https://www.malwarebytes.com/blog/feed/index.xml RSS
    Imported
    September 29, 2026 11:00
    Versions
    1 recorded
    Identity
    https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-coul...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.