Apple released emergency security updates on Monday for iOS, iPadOS and macOS to close CVE-2026-86950, an out-of-bounds write in CoreGraphics — the framework that handles graphics and image rendering across the company's platforms — that can be triggered by a maliciously crafted file and could lead to arbitrary code execution.

In its security notes, Apple said the flaw was "addressed with improved bounds checking" and credited Meta Product Security with discovering and reporting it. The company added the warning it reserves for serious cases: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."

Apple did not say how many people were targeted, whether any attacks succeeded, or when exploitation began. Because the vulnerable code also ships in iPadOS and macOS, the same class of attack surface exists on tablets and Macs, not just iPhones.

Fixes are available in iOS 26.7.1 and iPadOS 26.7.1 for iPhone 11 and later and recent iPads, in macOS Tahoe 26.7.1, and in macOS Sequoia 15.8.1. The mitigation only takes effect once the update is installed, so users on those releases should install promptly.

The same release wave carried routine bug-fix updates for the newest systems: iOS and iPadOS 27.0.1, macOS 27.0.1, watchOS 27.0.1 and visionOS 27.0.1. According to Apple, iOS 27.0.1 fixes a Face ID problem on iPhone 18 Pro and iPhone 18 Pro Max, a colour artifact that appeared with the f/1.48 aperture at 2× zoom under certain lighting on a "small number" of the new iPhones, and touchscreen issues when Notification Centre and Control Centre were active at the same time.

Notably absent from the batch are updates for visionOS 26, watchOS 26 and tvOS 26, the previous-generation platforms. Some older Apple TV and Apple Watch hardware cannot move to the version 27 line at all because Apple has cut off compatibility, leaving those devices without a patched path for this class of bug, at least for now.

The disclosure continues a pattern: Apple patched a memory-corruption flaw in dyld (CVE-2026-20700) in February, also citing sophisticated attacks. For defenders, the takeaway is the same each time — targeted exploitation of Apple platforms is real, the advisory arrives after the fact, and the only available mitigation is to update.