Apple released a security update on Monday to close a flaw that attackers may have already used to take control of iPhones. Users on iOS 26 should install the patch immediately to prevent arbitrary code execution. The vulnerability affects the CoreGraphics framework, which handles image and PDF rendering on the device. Without this fix, a malicious file could allow an attacker to run unauthorized code on your phone.
iOS 26.7.1 update fixes arbitrary code execution in CoreGraphics framework
The update arrives as iOS 26.7.1 and iPadOS 26.7.1, targeting devices running that specific version line. Apple also released macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the same CoreGraphics issue on computers. This ensures that users on the current Mac operating systems are protected against the same exploit vector. The patch covers the primary graphics processing layer used by the system.
- iOS Version: 26.7.1
- iPadOS Version: 26.7.1
- macOS Version: Tahoe 26.7.1
- macOS Version: Sequoia 15.8.1
- iOS Bug Fix Version: 27.0.1
Apple did not disclose how many people were targeted by the exploit or whether the attacks succeeded. Security researchers at the SANS Internet Storm Center and Meta Product Security have noted the potential for sophisticated targeted attacks. The flaw allows arbitrary code execution if a user opens a maliciously crafted file. This type of vulnerability is particularly dangerous because it allows arbitrary code execution.
A separate bug-fix release, iOS 27.0.1, addresses Face ID restart issues on iPhone 18 Pro and iPhone 18 Pro Max models. This update is distinct from the security patch and focuses on biometric authentication stability. Older devices that do not support iOS 26 received no updates on Monday. Users on those older versions are left without a fix for this specific CoreGraphics flaw.
Source: NotebookCheck




Discussion
0 comments