Apple Discovers Zero-Click iOS Flaw Tied to Targeted Spyware Attacks

Apple has rushed out emergency updates for a zero-click flaw that can run code on devices with no tap from the user.
The company says an out-of-bounds write in CoreGraphics, tracked as CVE-2026-86950, may have been exploited in extremely sophisticated attacks against specific people on older iOS versions.
Apple described the impact.
“Processing a maliciously crafted file may lead to arbitrary code execution.”
Meta’s product security team reported the bug, and Apple shipped iOS 26.7.1, iPadOS 26.7.1 and matching macOS fixes on September 28th of 2026 for iPhone 11 and later plus compatible iPads and Macs.
Just processing a malicious file, including a preview in some cases, can be enough, with no click required.
The Cybersecurity and Infrastructure Security Agency gave federal agencies three days to install the patch and check systems for compromise.
The episode fits a longer spyware arms race against Apple devices, after earlier threat notices to targeted users in more than 110 countries, reports Computerworld.
Follow us on X, Facebook and Telegram
Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
The post Apple Discovers Zero-Click iOS Flaw Tied to Targeted Spyware Attacks appeared first on The Daily Hodl.