If you’re waiting to download iOS 27 and all the cool new features it brings, you should definitely worry about downloading iOS 26.7.1 or iPadOS 26.7.1. This new update fixes a critical zero-day security vulnerability that may have already affected a number of Apple users. Additionally, this security update is also available in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
According to Apple’s release notes for the iPad and iPhone update, the company encountered an out-of-bounds write issue for CoreGraphics (Apple’s low-level 2D graphics framework) that Apple says “may have been exploited in a highly sophisticated attack” against those who have not yet upgraded to the latest operating system. This iOS 26 update fixes the issue, which received a severity rating of 8.8 out of 10.
For those who need a reminder, you can check for an update for iPad or iPhone by going to Settings > General > Software Update. Select Download and install if there is one available. Be sure not to confuse security updates 26.7.1 with the latest iOS 27.0.1 update, which fixes, among other things, some Face ID bugs for the iPhone 18 Pro. Those waiting to download iOS 27 should definitely check the security patch, but there are other things you also need to do to prepare your iPhone for iOS 27.
iOS 26 and iPadOS 26 users should download this security patch now
Those using iOS 26, iPadOS 26, macOS Sequoia or Tahoe are strongly advised by Apple to download the latest iOS 26.7.1 update as soon as possible. According to the National Vulnerability Database (via TechRadar), the CVE-2026-86950 vulnerability can allow hackers to use a malicious file to execute arbitrary code. Interestingly, Apple’s use of the phrase “against specific targeted individuals” suggests that this CoreGraphics attack could potentially affect high-profile individuals such as journalists or CEOs.
Affected devices include iPhone 11 and later; First-generation 11-inch iPad Pro and later, third-generation 12.9-inch iPad Pro and later, third-generation iPad Air and later, eighth-generation iPad and later, fifth-generation iPad mini and later, and Mac running macOS Sequoia 15.8.1 or Tahoe 26.7.1. In addition to making sure their devices are properly updated, iOS users may also want to check the various iPhone security settings that need to be enabled.
For those already using iOS or iPadOS 27, Apple makes no mention of published CVE entries, and the latest iOS 27.0.1 mainly contains bug fixes. Primarily, the update fixes an issue in the iPhone 18 Pro and Pro Max models that saw devices restart accidentally if Face ID failed to authenticate. The update also fixes a camera issue in these models that created color artifacts in certain lighting conditions when using the f/1.48 aperture, while a bug was also fixed for all iPhone users fixing an issue that would cause touchscreen issues if Control Center and Notification Center were open at the same time.
