Primary: Apple’s security notes for iOS 26.7.1 and iPadOS 26.7.1 (released September 28, 2026) list one CVE. Component: CoreGraphics. Impact: “Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” Fix: improved bounds checking for an out-of-bounds write. Credit: Meta Product Security.
Patched builds: iOS 26.7.1 / iPadOS 26.7.1 (iPhone 11 and later; iPad Pro 12.9-inch 3rd gen+, iPad Pro 11-inch 1st gen+, iPad Air 3rd gen+, iPad 8th gen+, iPad mini 5th gen+), macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 — same CVE on the Mac advisories. Apple’s same-day iOS/iPadOS 27.0.1, macOS Golden Gate 27.0.1, watchOS 27.0.1 and visionOS 27.0.1 carry no published CVE entries; Apple’s own wording scopes the exploitation report to iOS versions before iOS 27.
What is not public: how the file is delivered, whether a messaging app was the entry point, how many people were targeted, whether attempts succeeded, and who ran the campaign. SecurityWeek (Sep 29) notes it has asked Meta whether the flaw was exploited via WhatsApp — unanswered at publication; a WhatsApp chain is unconfirmed. CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R) per Rapid7’s CVE entry.
Update Sep 29 (midday): CISA’s machine-readable KEV feed bumped to catalogVersion 2026.09.29 (dateReleased 2026-09-29T13:51:33.3852Z) and lists CVE-2026-86950 as dateAdded 2026-09-29 — “Apple Multiple Products Out-of-Bounds Write Vulnerability” (CWE-787). Required action: apply vendor mitigations under BOD 26-04; dueDate 2026-10-02; forensicTriage Yes; knownRansomwareCampaignUse Unknown. Notes point to Apple’s three Sep 28 advisories (iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1). No separate CISA prose alert URL was published alongside the catalog row at check time; the KEV JSON + catalog page are the primary for the add.
POV: Named-target + Meta credit still reads like mercenary-spyware tradecraft, but Apple printed no attribution. With KEV live, FCEB clocks run through Oct 2 and everyone else should treat 26.7.1 / 15.8.1 as board-urgent on unmanaged fleets still below the iOS 27 line. Prioritize execs, journalists and high-risk users. Still watching for any Meta/WhatsApp companion advisory.
