Apple patches iOS flaw as SlowMist flags crypto wallet risk
Apple fixed a CoreGraphics flaw in iOS 26.7.1, and SlowMist told crypto holders to update devices, though no wallet drain has been confirmed.
Key takeaways
- The patch is out. iOS 26.7.1 and iPadOS 26.7.1 shipped on September 28 to fix CVE-2026-86950.
- Wallet theft unconfirmed. Apple has not confirmed any case where CVE-2026-86950 stole cryptocurrency or drained a wallet.
- AAPL slipped. AAPL traded at $331.48, down 2.04%, in the session covered by the report.
What happened
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28 to address CVE-2026-86950, a CoreGraphics flaw. Apple said a maliciously crafted file could lead to arbitrary code execution. The fix uses improved bounds checking. The bug is an out-of-bounds write, which lets data move past assigned memory limits.
Apple says the vulnerability may have been exploited against specifically targeted users before iOS 27. The company added that attackers may have exploited the flaw in highly advanced operations against specific people, and it credited Meta Product Security with the report. Apple did not name the targets, the file format or the delivery method, and the advisory ties the attacks to no hacking group or commercial surveillance vendor.
Affected devices include iPhone 11 and later models and supported iPad Pro, iPad Air, iPad and iPad mini models still on the iOS 26 or iPadOS 26 branch. Apple also patched the same CoreGraphics flaw in macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.
Why it matters
SlowMist warned crypto users about the update. The security firm said recent iOS attacks have reached sensitive wallet information directly, and a device compromise could expose wallet apps, authentication data, screenshots or notes holding recovery information. SlowMist has not linked any confirmed cryptocurrency theft to this specific flaw.
Apple has not confirmed any case where CVE-2026-86950 was used to steal cryptocurrency or drain wallets directly. Blockchain transfers usually cannot be reversed once attackers move funds from a compromised wallet, which keeps device security central for people who hold crypto on phones.
What the data shows
Apple Inc. (AAPL) shares traded at $331.48, down 2.04%, as the company released the update. AAPL fell 2.04% to $331.48 during Tuesday's session after Monday's $338.40 close. The available reports do not tie that decline to the vulnerability.
What is still unclear
- SlowMist has not publicly shown that this CVE was the flaw used in earlier crypto incidents.
- Apple's wording suggests exploitation happened before the flaw became public, the usual mark of a zero-day, though the company does not use that label.
Questions readers ask
Are crypto wallets at risk from the iOS update?
Apple has not confirmed any case where the flaw was used to steal crypto or drain a wallet. SlowMist flagged the patch for crypto holders after recent iOS attacks reached wallet data.
Which devices need the update?
The patch covers iPhone 11 and later models, plus supported iPad Pro, iPad Air, iPad and iPad mini models on the iOS 26 or iPadOS 26 branch. Apple also fixed the same CoreGraphics flaw on macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.
Did the Apple update affect AAPL stock?
AAPL dropped 2.04% to $331.48 in Tuesday's session, after closing at $338.40 on Monday. Reports do not tie the fall to the vulnerability.
Who reported CVE-2026-86950 to Apple?
Meta Product Security gets credit for reporting the issue, which Apple fixed through improved bounds checking.