Macworld
If you haven’t gotten around to updating your iPhone or Mac to OS 27, Apple hasn’t forgotten about you. Alongside iOS 27.0.1 and macOS 27.0.1 on Monday, Apple also released an update for older devices that can’t or don’t want to take the leap to OS 27.
You won’t get any new features, but the update patches a pretty serious security flaw for iOS 26, Tahoe, and Sequoia devices. According to Apple’s Security Updates page, 26.7.1 and 15.8.1 for macOS Sequoia contain a single CVE entry that is known to have been exploited:
CoreGraphics
- Impact: Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
- Description: An out-of-bounds write issue was addressed with improved bounds checking.
- CVE-2026-86950: Meta Product Security
The phrase “extremely sophisticated attack” means most users don’t have to worry. It has historically been used to describe flaws that were exploited to target specific groups of people, such as government officials or journalists. The flaw appears to have been patched ahead of the OS 27 releases, as it is not included in the original release nor as part of the 27.0.1 updates that arrived on Monday.
To update your devices, head over to System Settings (on a Mac) or Settings (on anything else), select General and then Software Update, and follow the prompts.