Skip to content
Apple patches iPhone flaw used in 'extremely sophisticated' attacks, crypto wallets at risk

Apple patches iPhone flaw used in 'extremely sophisticated' attacks, crypto wallets at risk

Finance.Yahoo • September 29, 2026

Apple (Nasdaq: AAPL) released an emergency-grade security update on Sept. 28, and this one is not routine, the company says the flaw it fixes may already have been used in real attacks, and a blockchain security firm is warning that crypto wallet holders have particular reason to install it.

The update, iOS 26.7.1 and iPadOS 26.7.1, closes a vulnerability tracked as CVE-2026-86950 in CoreGraphics, the framework iPhones and iPads use to render images.

Related: Google, Apple's new job postings go viral

A malicious file is all it takes

In plain terms, the bug let a specially crafted file, such as an image, write data outside the patch of memory it was assigned, a class of flaw known as an out-of-bounds write.

Once an attacker can scribble into memory that doesn't belong to the file, they can corrupt what's there and, in the worst case, run their own code on the device. The victim doesn't need to install anything; processing the booby-trapped file is enough.

Apple said it is "aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."

That is the language Apple typically reserves for exploits linked to advanced spyware operations aimed at chosen victims rather than mass campaigns.

Most Popular on TheStreet Roundtable:

JPMorgan sends optimistic message on Bitcoin price movement

JPMorgan sends optimistic message on Bitcoin price movement

Michael Saylor's Strategy just bought more Bitcoin, this purchase was 75% bigger

Michael Saylor's Strategy just bought more Bitcoin, this purchase was 75% bigger

California governor signs 'Opposite of Trump' bill

California governor signs 'Opposite of Trump' bill

Blockchain security firm alerts crypto users

Blockchain security firm SlowMist said the update is especially relevant to cryptocurrency users because it has observed iOS exploitation activity targeting sensitive wallet data.

The logic is straightforward: a phone that an attacker can run code on is a phone whose wallet apps, seed phrases stored in screenshots or notes, and two-factor codes are all up for grabs, and unlike a drained bank account, stolen crypto rarely comes back.

SlowMist did not attribute any specific crypto theft to CVE-2026-86950. The warning is the category of risk, not a confirmed heist.

Update now: Settings, General, Software Update.

The patch is available for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

Beyond updating, SlowMist's advice is the standard hygiene that matters most when exploits are in the wild: install apps only from trusted sources, don't open suspicious links in Safari or in-app browsers, and treat unexpected files, links, and app installation prompts with caution.

Extracted Entities

Attack Types (1)

Platforms (2)