Apple has released a critical security update for iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics framework. The flaw could allow arbitrary code execution after a device processes a maliciously crafted file, and Apple confirmed it was aware of a report indicating the vulnerability may have been exploited in an extremely sophisticated attack against specific targeted individuals running iOS versions released before iOS 27.
The vulnerability was reported by Meta Product Security and was fixed with improved bounds checking. Blockchain security firm SlowMist has warned that the patch is highly relevant to cryptocurrency users, noting that it has observed iOS exploitation activity targeting sensitive wallet data. SlowMist said the update addresses an out-of-bounds write vulnerability that may lead to arbitrary code execution, and described the issue as especially concerning for crypto users given recent attack patterns.
Apple itself has not stated that CVE-2026-86950 was specifically used to steal cryptocurrency, and SlowMist has not publicly established that this exact vulnerability was the one used in previously investigated wallet thefts. However, the warning follows SlowMist’s investigation of a malicious iOS application called FomoPeek, which contained kernel exploits capable of escaping Apple’s application sandbox and potentially accessing Keychain information and files stored by other apps. The broader crypto market has shown mixed signals, but this security update underscores the importance of device security for investors managing digital assets.