Apple has released an emergency security update fixing a critical iPhone vulnerability that the company says was already exploited in sophisticated, targeted attacks against specific individuals, a flaw blockchain security firm SlowMist warns is especially relevant to cryptocurrency users who manage wallets and trade from their phones.
Apple confirms possible exploitation in sophisticated attacks
Apple’s security advisory identifies CVE-2026-86950 as an out-of-bounds write vulnerability affecting CoreGraphics, a framework responsible for rendering and processing graphical content across its operating systems.
The flaw could allow attackers to execute arbitrary code when a vulnerable device processes a specially crafted file. Such vulnerabilities can provide attackers with an opportunity to compromise a device, depending on the circumstances and other security protections in place.
Apple acknowledged that it had received a report suggesting the vulnerability might have been exploited in highly sophisticated attacks against specific individuals using older versions of iOS.
The company stated that the reported attacks targeted devices running operating systems released before iOS 27. However, it did not disclose the identities of the affected individuals, the number of potential victims or the methods used to deliver the malicious files.
Apple credited Meta Product Security with reporting the vulnerability. The company addressed the underlying issue through improved bounds checking, a security measure designed to prevent software from accessing memory outside permitted boundaries.
The disclosure of possible exploitation makes the vulnerability particularly noteworthy. However, Apple has not provided enough information to establish the full scope of the reported attacks.
SlowMist highlights potential risks for cryptocurrency users
The disclosure of CVE-2026-86950 has also drawn attention from the cryptocurrency security community, particularly because smartphones have become essential tools for managing digital assets.
Blockchain security firm SlowMist warned that the vulnerability is especially relevant to cryptocurrency users. Many investors rely on their iPhones to access trading platforms, interact with decentralized applications and manage mobile cryptocurrency wallets.
A successful compromise could potentially expose sensitive information or create opportunities for further attacks, depending on the attacker’s access and the device’s security protections.
However, the vulnerability itself does not automatically grant attackers access to cryptocurrency wallets or private keys. Additional security weaknesses or successful exploitation of other components may be necessary to compromise protected assets.
Nevertheless, the possibility of arbitrary code execution presents a concern for users who conduct financial transactions through their smartphones.
Sophisticated attackers could potentially exploit vulnerabilities as part of a broader campaign targeting individuals with valuable digital assets. Such attacks may involve multiple stages, although there is currently no publicly confirmed evidence connecting CVE-2026-86950 to a specific cryptocurrency theft campaign.
The distinction is important: while the vulnerability creates a potential security risk, there is no verified indication that cryptocurrency wallets have been compromised through this particular flaw.
Apple releases security updates for iPhones and Macs
Apple addressed CVE-2026-86950 through several software updates released on September 28, providing fixes for affected iPhones, iPads and Mac computers.
The iPhone and iPad patches are included in iOS 26.7.1 and iPadOS 26.7.1. Apple also released macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to resolve the vulnerability on supported computers.
The updates address the underlying out-of-bounds write issue by improving how the operating systems validate memory boundaries when processing files.
Apple’s advisory lists the iPhone 11 and newer models among the supported devices receiving the iOS update. Compatible iPads are also covered by the corresponding iPadOS release.
Users can install the updates by opening their device’s Settings application, selecting General and navigating to Software Update. Mac users can check for the relevant security patches through System Settings.
Installing the appropriate update is particularly important for users who continue running older operating system versions. Once a vulnerability becomes public, unpatched devices may face additional risks if attackers develop or adapt methods to exploit it.
Although Apple has not disclosed the technical details of the reported attacks, the company’s acknowledgment of possible exploitation underscores the importance of applying security updates promptly.
For cryptocurrency users, keeping devices updated should remain part of a broader security strategy that includes protecting recovery phrases, enabling strong authentication and avoiding suspicious files.
The latest disclosure does not establish that cryptocurrency wallets have been compromised. However, the combination of a potentially exploitable software flaw and reported targeted attacks highlights the importance of maintaining secure devices when managing digital assets.