Back to the deskहिन्दी में पढ़ें

Advisory summary

Update now: iPhone fix for a targeted zero-day (iOS 26.7.1) and Chrome 154

Severity: CriticalPublished GlobalAdvisory2026-1001-IC03 min readBy Vivek Kumar
Illustration of a phone and a laptop each showing an 'Update available' screen with a shield, in front of a cracked warning sign tagged ZERO-DAY. Text: UPDATE NOW.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

Apple has fixed an iPhone and Mac flaw that it says may have been exploited against specific targeted people. Chrome 154 fixes 32 more; Google has not said any is exploited. Versions, who is affected and how to update.

01 / What happened

Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 on 28 September 2026. Each fixes one flaw, CVE-2026-86950 (CVE: the public ID for a security bug), an out-of-bounds write in CoreGraphics, Apple's 2D drawing framework. A maliciously crafted file may let an attacker run code on the device.

Apple says it is aware of a report that the flaw 'may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27'. If so, it was a zero-day: a flaw attacked before a fix existed. Apple credits Meta Product Security. On 29 September the US agency CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue, giving federal agencies until 2 October. CERT-In's note CIVN-2026-0485 (1 October) rates it High.

On 29 September, Google released desktop Chrome 154.0.8037.92/.93 for Windows and Mac and 154.0.8037.92 for Linux, with 32 security fixes: one rated Critical (CVE-2026-102331) and 25 High. Google has not said any is being exploited. CERT-In's note CIVN-2026-0486 (1 October) rates them Critical. Chrome 154.0.8037.92 for Android has the same fixes unless otherwise noted, Google says.

02 / Who is affected

  • iPhone and iPad on version 26: anything before 26.7.1. The fix covers every device on version 26 (iPhone 11 and later).
  • Mac: Tahoe before 26.7.1 and Sequoia before 15.8.1.
  • iOS 27 and macOS Golden Gate 27: not listed as affected. Apple says their 27.0.1 updates have 'no published CVE entries'.
  • Older devices: iOS 18 is the last version for iPhone XS, XS Max, XR and iPad (7th generation). Apple has published no iOS 18 fix and does not say whether iOS 18, or older macOS such as Sonoma, is affected. No workaround has been described, The Hacker News notes; on these devices, be wary of unexpected PDFs and other files.
  • Chrome: versions before 154.0.8037.92 on Windows, Mac, Linux and Android.

03 / Confirmed, reported, claimed

Confirmed (Apple, CISA, CERT-In, Google): the versions and CVE IDs above, Apple's 'may have been exploited' statement, and CISA's KEV listing 'based on evidence of active exploitation'. CERT-In goes further than Apple, saying the flaw 'is being actively exploited'.

Reported (The Hacker News): on 30 September the security firm Calif published scripts that build a PDF with a crafted font, which crashed Calif's test program on an unpatched Mac (with a debugger trace). A crash is not a working attack. The Hacker News calls Calif's WhatsApp clues circumstantial; Calif's post does not test a WhatsApp delivery path, and Calif deleted a sentence speculating about one 85 minutes after publishing.

Claimed (Calif, unverified): the file also triggers the bug on iOS (no iOS trace was published), and new PDF font checks in WhatsApp 26.38.74 hint at a possible delivery route.

Not known: who was targeted, by whom, how many, or how the files arrived. WhatsApp has published no advisory linking the flaw to its app.

'Targeted' describes who was attacked, not who can skip the update.

04 / How to update

  • iPhone or iPad: Settings, General, Software Update, Download and Install: 26.7.1 on version 26, 27.0.1 on iOS 27.
  • Mac: Apple menu, System Settings, General, Software Update, then install the update offered.
  • Chrome on a computer: three-dot menu, Help, About Google Chrome, then Relaunch. You want 154.0.8037.92 or later. Google says it rolls out 'over the coming days/weeks', so check rather than wait.
  • Chrome on Android: Play Store, profile icon, Manage apps & device, then update Chrome under 'Updates available'. Google says it reaches Google Play 'over the next few days'; if it is not listed yet, check again later.
  • Update only from these screens. Fake 'update your browser' pop-ups are a known lure for loader malware such as SocGholish. Never install Chrome from an APK file sent in a chat.

05 / If you could be a target, and for IT teams

  • Journalists, activists and others who could be personally targeted can also turn on Lockdown Mode (Settings, Privacy & Security), which Apple calls 'an optional, extreme protection'. Apple has not said whether Lockdown Mode would have blocked the reported attacks, The Hacker News notes, so update first.
  • IT teams: push the updates through device management; see our KEV digest for 29 September and the KEV tracker. Organisations covered by CERT-In's directions must report specified incidents within 6 hours: how to report to CERT-In.

Source log / 2026-1001-IC

Explainers & profilesMalicious APK scam on WhatsApp
More from the archive