The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Yes—install the latest security update available for your iPhone or iPad. Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, to fix CVE-2026-86950, a CoreGraphics flaw that Apple says may have been exploited in an attack against specific targeted individuals. Apple has not publicly identified the attackers, the delivery method, the number of victims, or whether spyware was involved.
What does CVE-2026-86950 do?
The vulnerability is an out-of-bounds write in CoreGraphics, the system component that handles graphics-related processing. Apple says processing a maliciously crafted file may lead to arbitrary code execution. In other words, the flaw could allow code to run under some conditions when a vulnerable device processes a specially crafted file; Apple’s public advisory does not explain how such a file reached a device.
Apple’s September 28, 2026 advisory says the company is aware of a report that CVE-2026-86950 may have been exploited in “an extremely sophisticated attack against specific targeted individuals” on versions before iOS 27. The Cyber Security Agency of Singapore assigns the flaw a CVSS v3.1 score of 8.8 out of 10.
Do I need to update my iPhone now?
Yes. Install the latest Apple security update offered for your device. Apple’s September 28 releases include iOS 26.7.1 and iPadOS 26.7.1, which address the flaw. The Singapore Cyber Security Agency recommends immediate updating and identifies versions before iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 as affected. Check Apple’s current security releases for the newest version applicable to your device: Apple security releases.
#1 Best Overall
- This phone is unlocked and compatible with any carrier of choice on GSM and CDMA networks (e.g. AT&T, T-Mobile, Sprint, Verizon, US Cellular, Cricket, Metro, Tracfone, Mint Mobile, etc.).
- Please check with your carrier to verify compatibility.
- When you receive the phone, insert a SIM card from a compatible carrier. Then, turn it on, connect to Wi-Fi, and follow the on screen prompts to activate service.
- The device does not come with headphones or a SIM card. It does include a generic (Mfi certified) charger and charging cable.
- Tested for battery health and guaranteed to have a minimum battery capacity of 80%.
How to install the update
- On iPhone or iPad: Open Settings, then go to General > Software Update. Follow the onscreen instructions to install the latest available update.
- On Mac: Open the Apple menu, choose System Settings, then General > Software Update. Install the latest update offered for your macOS version.
- Check again afterward: Return to Software Update and confirm that the device reports it is up to date. Apple may offer a newer applicable release than the versions named in the September 28 alert.
Which Apple devices and software versions are affected?
Apple’s advisory lists iPhone 11 and later and specified iPad generations. The Singapore Cyber Security Agency states these affected version cutoffs:
| Platform | Affected versions identified by the agency | Fixed release named in the alert |
|---|---|---|
| iPhone | Before iOS 26.7.1 | iOS 26.7.1 |
| iPad | Before iPadOS 26.7.1 | iPadOS 26.7.1 |
| Mac with macOS Tahoe | Before macOS Tahoe 26.7.1 | macOS Tahoe 26.7.1 |
| Mac with macOS Sequoia | Before macOS Sequoia 15.8.1 | macOS Sequoia 15.8.1 |
These are the cutoffs in the agency’s alert, not a guarantee that every device can install every listed release. Apple provides device-specific release details in its security releases and security update information.
Rank #2
- This phone is unlocked and compatible with any carrier of choice on GSM and CDMA networks (e.g. AT&T, T-Mobile, Sprint, Verizon, US Cellular, Cricket, Metro, Tracfone, Mint Mobile, etc.).
- Please check with your carrier to verify compatibility.
- When you receive the phone, insert a SIM card from a compatible carrier. Then, turn it on, connect to Wi-Fi, and follow the on screen prompts to activate service.
- The device does not come with headphones or a SIM card. It does include a generic (Mfi certified) charger and charging cable.
- Tested for battery health and guaranteed to have a minimum battery capacity of 80%.
What is known—and not known—about the reported attack?
Apple’s notice reports possible exploitation against specific targeted individuals. It does not say who carried out the operation, how many people were affected, or whether attackers used spyware. It also does not identify a delivery channel: claims that the vulnerability was delivered through a website, email, message, or another route are not established by Apple’s public advisory. TechCrunch likewise reports that attacker identities and the victim count remain unclear.
The targeted-attack warning is a reason to patch promptly, but it does not establish that ordinary users were targeted or that every device running an older version was attacked. The vulnerability’s severity score is a technical rating, not a count or measure of confirmed victims.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- This phone is unlocked and compatible with any carrier of choice on GSM and CDMA networks (e.g. AT&T, T-Mobile, Sprint, Verizon, US Cellular, Cricket, Metro, Tracfone, Mint Mobile, etc.).
- Please check with your carrier to verify compatibility.
- When you receive the phone, insert a SIM card from a compatible carrier. Then, turn it on, connect to Wi-Fi, and follow the on screen prompts to activate service.
- The device does not come with headphones or a SIM card. It does include a generic (Mfi certified) charger and charging cable.
- Tested for battery health and guaranteed to have a minimum battery capacity of 80%.
How this patch fits the wider spyware context
Apple’s urgent fix arrives amid wider concern about targeted surveillance, but separate incidents should not be conflated with CVE-2026-86950. TechCrunch reported a distinct issue, CVE-2026-86869, which ironPeak described as a zero-click flaw involving a crafted iMessage and Apple’s BlastDoor messaging security feature. According to TechCrunch, Apple fixed that separate issue with iOS 27, iPadOS 27, and macOS 27; it was not known whether CVE-2026-86869 had been exploited before the fix. That reporting does not establish the delivery path for CVE-2026-86950.
TechCrunch reported on September 29, 2026, citing Apple’s statistics, that almost four out of five iPhone owners were still running iOS 26. This is a dated adoption snapshot, not a current or globally complete measure. Separately, Computerworld reported that Apple sent threat warnings to customers in 110 countries in August 2026; that figure describes the reach of those warnings, not victims of this vulnerability.
Rank #4
- Please check with your carrier to verify compatibility.
- Tested for battery health and guaranteed to have a minimum battery capacity of 80%.
What else should users do?
The operating-system update is the direct response to this flaw. General precautions—such as avoiding untrusted apps, suspicious links, and unexpected prompts to install files or apps—can reduce security risks, but they are not substitutes for patching CVE-2026-86950.
Lockdown Mode may be relevant to people who have received an Apple threat notification or face an elevated risk of targeted attacks. It is not a replacement for installing the update, and it does not guarantee protection from every attack. Computerworld quoted Apple spokesperson Sarah O’Rourke as saying: “We are not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device.” That statement is limited to the attacks Apple is aware of and to devices with Lockdown Mode enabled.
Quick Recap
Best Value
- This phone is unlocked and compatible with any carrier of choice on GSM and CDMA networks (e.g. AT&T, T-Mobile, Sprint, Verizon, US Cellular, Cricket, Metro, Tracfone, Mint Mobile, etc.).
- Please check with your carrier to verify compatibility.
- When you receive the phone, insert a SIM card from a compatible carrier. Then, turn it on, connect to Wi-Fi, and follow the on screen prompts to activate service.
- The device does not come with headphones or a SIM card. It does include a generic (Mfi certified) charger and charging cable.
- Tested for battery health and guaranteed to have a minimum battery capacity of 80%.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

