All security updates
AppleUpdate promptlySecurity updateAutomatically summarised from official sources

iOS 26.7.1 and iPadOS 26.7.1

Apple released iOS 26.7.1 and iPadOS 26.7.1 on 2026-09-28. This release fixes security vulnerabilities — see the technical details below.

Manufacturer release date: 2026-09-28

Article last updated: 2026-10-05

Sources last checked: 2026-10-05

What changed

Apple publishes the fixed vulnerabilities in its security content advisory for this release. Use the official release page below for the current details.

Why it matters

If your device is running an earlier version of the affected software, updating closes the vulnerabilities listed below.

What to do

On the device, open Settings > General > Software Update and install the version Apple offers.

Open Settings > General > Software Update (iPhone/iPad) or System Settings > General > Software Update (Mac) to see the installed version.

Apple: Update the software on your iPhone or iPad

Updates only reach the model generations Apple lists for each release. Older devices stay on an older branch — check Apple's security releases page for which branch the model receives.

Affected devices and versions

Covers: iPhone / iOS, iPad / iPadOS.

Applies to: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, iPad mini 5th generation and later.

We don't know which software your device is running. If your device is running an affected version, updating is the recommended action — check the installed version with the steps above.

Security fixes in this release

This release fixes 1 vulnerability, including 1 known-exploited — see the technical details below.

Fixes known-exploited vulnerabilities

  • The fix is this release: iOS 26.7.1 and iPadOS 26.7.1 (released 2026-09-28). Devices running an affected version should update promptly.
  • Affected versions: iPadOS (versions before 26.7.1).
  • Exploitation evidence: CVE-2026-86950 — Known exploited — added to CISA's Known Exploited Vulnerabilities catalogue on 2026-09-29.

"Known exploited" comes from CISA's Known Exploited Vulnerabilities catalogue for the affected product components — it is not confirmed exploitation on your own device, and we can't know which software your device runs. Check the installed version with the steps above.

Technical details (1 vulnerability)

CVE-2026-86950

Impact: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1.

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Affected versions in the official record: iPadOS (versions before 26.7.1)

Severity: 8.8 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 8.8 (HIGH); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Known exploited — added to CISA's Known Exploited Vulnerabilities catalogue on 2026-09-29 This refers to the CVE listing — not to confirmed exploitation on this specific product.

Source: Official CVE record (CVE List / NVD); CISA Known Exploited Vulnerabilities catalogue

The full CVE list for this release is above. Individual vulnerability details come from the official CVE record (CVE List / NVD) and the manufacturer's own advisory where published.

Official sources

Record history

  • 2026-10-05 — published: Initial automated publication from official sources.

This article is automatically summarised from official sources. It isn't a manual editorial review. Guidance can help reduce risk. No setting or service can guarantee complete online safety.

Spotted something inaccurate in this article?Share feedback