iOS

iOS 26.7.1 Plugs Security Hole Used in Targeted Attacks

iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 – all released on Monday – address a major security vulnerability that Apple believes was used in the wild against a small number of people.

Apple’s security support pages say the updates fix a CoreGraphics out-of-bounds write issue that bad actors could exploit using a maliciously crafted file, allowing for arbitrary code execution. The issue has been fixed with improved bounds checking.

Apple says the flaw was exploited in an “extremely sophisticated attack” on targeted individuals. Apple’s latest operating systems apparently are not affected, as the iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 updates that were also released on Monday, have no published CVE entries.

Users still running an earlier version of iOS 26, iPadOS 26, macOS Tahoe, or macOS Sequoia, are advised to install the new updates as soon as possible. Now that the vulnerability has been made public, bad guys could expand attacks against users who haven’t updated their devices.

Chris Hauk

Chris is a Senior Editor at Mactrast. He lives somewhere in the deep Southern part of America, and yes, he has to pump in both sunshine and the Internet.