Basic graphics
- Impact: Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report indicating that this issue may have been exploited in an extremely sophisticated attack against targeted individuals on versions of iOS prior to iOS 27.
- Description: An out-of-bounds write issue was fixed by improving bounds checking.
- CVE-2026-86950: Metaproduct Security
The phrase “extremely sophisticated attack” means that most users have nothing to worry about. Historically it has been used to describe flaws that were exploited to attack specific groups of people, such as government officials or journalists. The bug appears to have been fixed before OS 27 releases, as it is not included in the original release nor as part of the 27.0.1 updates that arrived on Monday.
To update your devices, go to System Settings (on a Mac) or Settings (on anything else), select General and then Software updateand follow the directions.