Brief

Apple releases urgent iOS 26 patch for zero‑click exploit

The update addresses CVE‑2026‑86950 and follows a warning from Meta’s security team.

By Felo News Desk · Published

Apple has rolled out an emergency security update for iOS 26, iPadOS 26 and macOS Sequoia to fix a zero‑click CoreGraphics vulnerability (CVE‑2026‑86950), according to Computerworld.

The flaw, described as an out‑of‑bounds write issue, could allow arbitrary code execution simply by previewing a malicious file, without any user interaction. Apple said it learned of a targeted attack on older iOS versions through a tip‑off from Meta’s product security team.

Security firm SlowMist later reported seeing exploitation activity aimed at cryptocurrency wallet data, underscoring the risk of zero‑click attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) instructed federal agencies to apply the patch within three days and to run forensic checks for possible compromise.

Apple’s earlier iOS 26.7.1 patch also addressed the same CoreGraphics issue, urging users to update immediately.

Key facts

  • Apple released an emergency patch for iOS 26, iPadOS 26 and macOS Sequoia to fix CVE‑2026‑86950. (computerworld.com)
  • The vulnerability is a zero‑click out‑of‑bounds write issue in CoreGraphics that could allow arbitrary code execution. (computerworld.com)
  • Apple was alerted to a targeted exploit by Meta’s product security team. (computerworld.com)
  • CISA gave U.S. federal agencies three days to install the patch and conduct forensic testing. (computerworld.com)
  • Blockchain security firm SlowMist observed exploitation attempts aimed at cryptocurrency wallet data. (computerworld.com)

Sources

  • [1] computerworld.com — originally reported as “Apple issues urgent iOS patch as it navigates the spyware arms race”

Earlier coverage

More from WAR

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com