Apple Rushes Fix for Exploited iOS 26 Bug as Users Delay iOS 27 Upgrade

Apple Fixes Actively Exploited iOS 26 Security Flaw in New Update

Apple has released a fresh round of software updates, including an important security patch for users who have not yet upgraded to iOS 27. The update, iOS 26.7.1 and iPadOS 26.7.1, addresses a serious vulnerability in CoreGraphics, a key system framework used to process images, PDFs, and other visual content across Apple devices.

According to Apple’s security advisory, the flaw could allow a maliciously crafted file to trigger arbitrary code execution. In simple terms, opening or processing a dangerous file could potentially let an attacker run code on the device without the user’s permission.

Apple also stated that the issue may have already been used in a highly sophisticated attack targeting specific individuals running versions of iOS earlier than iOS 27. The vulnerability was reported by Meta Product Security. Apple has not shared how many users were targeted, whether the attacks were successful, or who may have been behind them.

For anyone still using iOS 26, this makes the latest update especially important. Even if you are not planning to move to iOS 27 yet, installing iOS 26.7.1 is strongly recommended to close the security gap.

iOS 27 appears to be unaffected

Apple has not listed any security fixes for iOS 27.0.1 or macOS 27.0.1 related to this flaw, suggesting that the newest major operating system versions are not affected. Apple’s wording also points to the issue being limited to devices running software earlier than iOS 27.

That means the main group at risk includes users who delayed the September upgrade to iOS 27. Apple continues to provide security updates for iOS 26, but users must install them manually.

To check for the update, go to Settings, then General, then Software Update. Apple lists iOS 26.7.1 separately from the option to upgrade to iOS 27.

Some iPads cannot upgrade to iPadOS 27, so Apple has provided iPadOS 26.7.1 for affected models. These include the 12.9-inch iPad Pro 3rd generation, 11-inch iPad Pro 1st generation, iPad Air 3rd generation, iPad 8th generation, and iPad mini 5th generation.

Mac users also received related security fixes. Apple released macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the same CoreGraphics issue. However, devices that no longer receive iOS 26 updates did not get a patch in this release, and Apple has not confirmed whether older unsupported versions are vulnerable.

iOS 27.0.1 brings key bug fixes for newer iPhones

For users who have already moved to iOS 27, Apple also released iOS 27.0.1. This update does not include listed security fixes, but it does resolve several bugs affecting newer devices.

One of the main fixes targets the iPhone 18 Pro and iPhone 18 Pro Max. Apple says these devices may unexpectedly restart when Face ID fails to authenticate. The update is designed to correct that problem and improve overall reliability.

iOS 27.0.1 also fixes an issue that caused color artifacts to appear in some photos taken at 2x zoom. Another bug involving the touchscreen has also been resolved. In some cases, the display could stop responding when Notification Center and Control Center were opened at the same time.

Apple also released watchOS 27.0.1 and visionOS 27.0.1 on the same day. These updates appear to focus on bug fixes, as Apple did not list new security entries for them.

Why this update matters

Security updates like iOS 26.7.1 are important because actively exploited vulnerabilities can be used in targeted attacks before the public knows many details. Even if Apple describes the attack as aimed at specific individuals, installing the patch helps protect all users from future attempts that may copy or adapt the same method.

If your iPhone or iPad is still running iOS 26 or iPadOS 26, updating as soon as possible is the safest move. If your device supports iOS 27, upgrading to the latest version may also provide broader protection along with the newest features and bug fixes.