iOS 27

iPhone

iPad

Apple Watch

AirPods

Apple Deals

If You Skipped iOS 27, There’s a New iPhone Update You Should Install Now Because Attackers Have Already Used the Flaw It Fixes

Gotechtor select and review products independently. When you purchase through our links, we may earn a commission. See our ethics statement.

Apple has released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to fix a security vulnerability that was already being used in attacks.

Apple says the flaw may have been exploited in an “extremely sophisticated attack” against specific targeted individuals running older versions of iOS.

If you’ve stayed on iOS 26 instead of upgrading to iOS 27, this is an update you shouldn’t put off.

A malicious file could allow code to run on your device

The vulnerability is in CoreGraphics, a framework Apple uses to handle graphics across its operating systems.

Apple describes the flaw as an out-of-bounds write. Processing a maliciously crafted file could allow an attacker to execute arbitrary code on the affected device.

An out-of-bounds write happens when software writes data outside the area of memory it was supposed to use.

Depending on where that data ends up and what protections an attacker can bypass, vulnerabilities like this can be used as part of an attack to gain control over a device.

Apple says it fixed the problem with improved bounds checking.

Apple says the flaw was already exploited

This isn’t a security vulnerability Apple discovered before anyone could use it. The company says it is aware of a report that the flaw may have been exploited against specific targeted individuals running versions of iOS before iOS 26.7.

That wording points to a limited attack rather than widespread exploitation, but it also means vulnerable devices shouldn’t be left unpatched simply because the original targets were narrowly selected.

Apple hasn’t disclosed who was targeted, who carried out the attacks, or how the malicious files were delivered.

iOS 27 users don’t need this update

The security fix is being distributed to devices remaining on Apple’s previous operating systems rather than through iOS 27.0.1 and the other current-generation updates released Monday.

Apple’s security documentation for iOS 27.0.1 and iPadOS 27.0.1 doesn’t list this vulnerability, indicating the affected code isn’t being patched there as part of Monday’s releases.

If you’re running iOS 26, you can install iOS 26.7.1 under Settings > General > Software Update.

Mac users remaining on macOS Tahoe or macOS Sequoia should install macOS 26.7.1 or macOS 15.8.1, respectively.

For devices that can’t move to Apple’s latest operating systems, these smaller security releases are particularly important.

They allow you to patch a vulnerability Apple knows has been exploited without requiring an upgrade to the newest major OS.

🍎 The only 5 Apple stories that matter — sent every Friday to 50K+ smart readers. You in?

Founder & Editor-in-Chief

Herby has a healthy obsession with all things Apple, especially the iPhone. He loves to rip things apart to see how they work. He is responsible for the editorial direction, strategy, and growth of Gotechtor.

Herby Jasmin

's latest stories

Leave a Comment

Be kind. Discriminatory language, personal attacks, promotion, and spam will be removed. Please read Gotechtor's Community Guidelines before participating.