BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Apple fixes critical flaw potentially tied to 'sophisticated' attack

On Sep. 28, Apple Inc. (Nasdaq: AAPL) released the security update iOS 26.7.1 and iPadOS 26.7.1. The update addresses CVE-2026-86950 through improved bounds checking. CVE-2026-86950 is an out

AnonymousCryptoCompass newsroom
September 29, 2026
2 min read
NEWS
Apple fixes critical flaw potentially tied to 'sophisticated' attack
CryptoCompass editorial visual for bitcoin coverage.

On Sep. 28, Apple Inc. (Nasdaq: AAPL) released the security update iOS 26.7.1 and iPadOS 26.7.1.

The update addresses CVE-2026-86950 through improved bounds checking. CVE-2026-86950 is an out-of-bounds write vulnerability that affects Apple's image rendering framework called CoreGraphics and allows arbitrary code execution when a device processes a maliciously crafted file.

Related: Google, Apple's new job postings go viral

An out-of-bounds write occurs when software writes data beyond an allocated memory area, creating conditions that attackers can potentially use to corrupt memory or run their own code.

Apple said it is "aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."

The security update is available for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

Blockchain security firm alerts crypto users 

The blockchain security firm called SlowMist said Apple's latest security update is particularly relevant to cryptocurrency users because it has observed the iOS exploitation activity targeting sensitive wallet data.

However, the security firm did not attribute any crypto hacking incident to CVE-2026-86950.

SlowMist urged Apple users to install the latest security updates on their devices, and avoid installing apps from unknown or untrusted sources. It also advised users to not open suspicious links in Safari or in-app browsers, and treat unexpected files, links, and app installation prompts with caution.

Related: Bitget CEO confirms $351.6M hack, withdrawals paused