Apple Patches Zero-Day Flaw Exploited in Targeted Attacks
Apple has fixed a zero-day flaw used in sophisticated targeted attacks. Here's what to update and why most people aren't at high risk.
Updated 2026-09-29
Apple has released security updates to fix a zero-day vulnerability in CoreGraphics, the framework iOS and macOS use to draw images, text and 2D graphics on screen. The flaw, tracked as CVE-2026-20700, was found to have been exploited in what Apple describes as an "extremely sophisticated" attack against specific targeted individuals. It was discovered by Meta's Product Security team and patched in updates released this week.
The issue is an out-of-bounds write weakness. In plain terms, a maliciously crafted file, such as an image, could trick a device into running code it shouldn't. Apple has fixed this by adding stronger bounds checking to CoreGraphics.
What this actually means for you
This was not a mass attack. Apple's own wording says it was used against specific targeted individuals, not the general public. That matters. It means most iPhone, iPad and Mac owners were never the target and are not currently at elevated risk.
What it does mean is that a working method existed to attack devices before most people had ever heard of it, and Apple has now closed that door with a software update. That's exactly how this is supposed to work: a flaw is found (in this case by a third party's security team), Apple fixes it, and everyone who updates is protected regardless of whether they were ever a target.
This is also the second zero-day Apple has fixed since the start of the year that was exploited in the wild, the first being a separate flaw in February. Two in one year is not unusual for Apple's ecosystem and is not, by itself, cause for alarm.
What to do
- Update your iPhone or iPad. Go to Settings > General > Software Update and install iOS 26.7.1 or iPadOS 26.7.1 if it's offered.
- Update your Mac. Go to System Settings > General > Software Update and install macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, whichever applies to your machine.
- Check which devices are covered. This affects iPhone 11 and later, most iPad Pro, iPad Air, iPad and iPad mini models from the last few years, and Macs on the two versions above. If your device is older than these, check whether an update is available for it anyway; if none appears, there is nothing further you can do on the software side.
- Don't delay it. Even though this flaw was used in a targeted way, once a fix is public, the underlying technique can sometimes be reverse-engineered by others. Installing the update promptly removes the risk regardless of who you are.
- You don't need to change any passwords because of this. There is no indication that passwords or other personal data were taken as part of this issue.
What this does not fix
A software update from Apple closes this one specific hole. It does not do several other things people sometimes assume it does.
It does not mean your phone is now immune to everything. New vulnerabilities are found regularly across every platform, and this patch only covers this particular flaw.
It does not protect you from scam messages, phishing links, or fraudulent calls that rely on tricking you rather than exploiting software. Those arrive through ordinary channels, texts, emails, messaging apps, and no operating system update stops them, because the weakness they target is human judgement, not code.
It does not tell you whether you personally were ever affected. Apple has not published a way for individual users to check this, and given the targeted nature of the attack, most people will simply never know either way. That's a reasonable outcome: the update protects you going forward regardless.
It does not replace basic caution around unfamiliar files, links or attachments, particularly from people or organisations you don't recognise. Updating your software is the right response to this specific news. It's not a substitute for the ordinary habits that guard against the far more common risks: unexpected links, urgent-sounding messages and requests to click before you think.
See what the internet sees Free, and it needs no account.