Apple patches exploited iOS 26 flaw for anyone skipping iOS 27

Apple shipped a batch of updates on Monday, and one of them fixes a flaw the company says may already have been exploited. iOS 26.7.1 and iPadOS 26.7.1 patch CoreGraphics, the graphics framework the system uses to render images and PDF files, among other things. According to Apple, a maliciously crafted file could lead to arbitrary code execution. The advisory says the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta Product Security reported it. Apple did not say how many people were targeted or whether the attacks succeeded.
iOS 27 is not affected
Apple lists no published CVE entries for iOS 27.0.1 or macOS 27.0.1. Johannes Ullrich of the SANS Internet Storm Center reads that to mean the current releases are not affected, which matches Apple's own wording. The people at risk are those who held off on the September upgrade to iOS 27. Apple still ships security fixes for iOS 26, but you have to install them. You will find iOS 26.7.1 under Settings > General > Software Update, where the upgrade to iOS 27 is listed separately.
iPadOS 27 does not support the 12.9-inch iPad Pro (3rd generation), the 11-inch iPad Pro (1st generation), the iPad Air (3rd generation), the iPad (8th generation) or the iPad mini (5th generation). All five get iPadOS 26.7.1 instead. On the Mac, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 fix the same flaw. Devices that no longer receive iOS 26 got nothing on Monday. Apple did not say whether older versions are affected.
iOS 27.0.1 fixes Face ID on the iPhone 18 Pro
If you are already on iOS 27, iOS 27.0.1 is a bug-fix release. The main fix is for the iPhone 18 Pro and iPhone 18 Pro Max, which according to Apple's release notes "may unexpectedly restart when Face ID fails to authenticate." Apple had confirmed the fix to 9to5Mac ahead of time. The update also removes color artifacts in some 2x zoom photos. A touchscreen that stopped responding when Notification Center and Control Center were opened at the same time is fixed as well. watchOS 27.0.1 and visionOS 27.0.1 arrived the same day, also without security entries.





