Advisory summary
Update now: iPhone fix for a targeted zero-day (iOS 26.7.1) and Chrome 154

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
Apple has fixed an iPhone and Mac flaw that it says may have been exploited against specific targeted people. Chrome 154 fixes 32 more; Google has not said any is exploited. Versions, who is affected and how to update.
01 / What happened
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 on 28 September 2026. Each fixes one flaw, CVE-2026-86950 (CVE: the public ID for a security bug), an out-of-bounds write in CoreGraphics, Apple's 2D drawing framework. A maliciously crafted file may let an attacker run code on the device.
Apple says it is aware of a report that the flaw 'may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27'. If so, it was a zero-day: a flaw attacked before a fix existed. Apple credits Meta Product Security. On 29 September the US agency CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue, giving federal agencies until 2 October. CERT-In's note CIVN-2026-0485 (1 October) rates it High.
On 29 September, Google released desktop Chrome 154.0.8037.92/.93 for Windows and Mac and 154.0.8037.92 for Linux, with 32 security fixes: one rated Critical (CVE-2026-102331) and 25 High. Google has not said any is being exploited. CERT-In's note CIVN-2026-0486 (1 October) rates them Critical. Chrome 154.0.8037.92 for Android has the same fixes unless otherwise noted, Google says.
02 / Who is affected
- iPhone and iPad on version 26: anything before 26.7.1. The fix covers every device on version 26 (iPhone 11 and later).
- Mac: Tahoe before 26.7.1 and Sequoia before 15.8.1.
- iOS 27 and macOS Golden Gate 27: not listed as affected. Apple says their 27.0.1 updates have 'no published CVE entries'.
- Older devices: iOS 18 is the last version for iPhone XS, XS Max, XR and iPad (7th generation). Apple has published no iOS 18 fix and does not say whether iOS 18, or older macOS such as Sonoma, is affected. No workaround has been described, The Hacker News notes; on these devices, be wary of unexpected PDFs and other files.
- Chrome: versions before 154.0.8037.92 on Windows, Mac, Linux and Android.
03 / Confirmed, reported, claimed
Confirmed (Apple, CISA, CERT-In, Google): the versions and CVE IDs above, Apple's 'may have been exploited' statement, and CISA's KEV listing 'based on evidence of active exploitation'. CERT-In goes further than Apple, saying the flaw 'is being actively exploited'.
Reported (The Hacker News): on 30 September the security firm Calif published scripts that build a PDF with a crafted font, which crashed Calif's test program on an unpatched Mac (with a debugger trace). A crash is not a working attack. The Hacker News calls Calif's WhatsApp clues circumstantial; Calif's post does not test a WhatsApp delivery path, and Calif deleted a sentence speculating about one 85 minutes after publishing.
Claimed (Calif, unverified): the file also triggers the bug on iOS (no iOS trace was published), and new PDF font checks in WhatsApp 26.38.74 hint at a possible delivery route.
Not known: who was targeted, by whom, how many, or how the files arrived. WhatsApp has published no advisory linking the flaw to its app.
'Targeted' describes who was attacked, not who can skip the update.
04 / How to update
- iPhone or iPad: Settings, General, Software Update, Download and Install: 26.7.1 on version 26, 27.0.1 on iOS 27.
- Mac: Apple menu, System Settings, General, Software Update, then install the update offered.
- Chrome on a computer: three-dot menu, Help, About Google Chrome, then Relaunch. You want 154.0.8037.92 or later. Google says it rolls out 'over the coming days/weeks', so check rather than wait.
- Chrome on Android: Play Store, profile icon, Manage apps & device, then update Chrome under 'Updates available'. Google says it reaches Google Play 'over the next few days'; if it is not listed yet, check again later.
- Update only from these screens. Fake 'update your browser' pop-ups are a known lure for loader malware such as SocGholish. Never install Chrome from an APK file sent in a chat.
05 / If you could be a target, and for IT teams
- Journalists, activists and others who could be personally targeted can also turn on Lockdown Mode (Settings, Privacy & Security), which Apple calls 'an optional, extreme protection'. Apple has not said whether Lockdown Mode would have blocked the reported attacks, The Hacker News notes, so update first.
- IT teams: push the updates through device management; see our KEV digest for 29 September and the KEV tracker. Organisations covered by CERT-In's directions must report specified incidents within 6 hours: how to report to CERT-In.
Source log / 2026-1001-IC
- Apple — About the security content of iOS 26.7.1 and iPadOS 26.7.1 (28 Sep 2026) Primary
- Apple — About the security content of macOS Tahoe 26.7.1 (28 Sep 2026) Primary
- Apple — About the security content of macOS Sequoia 15.8.1 (28 Sep 2026) Primary
- Apple — Apple security releases (iOS 27.0.1 and macOS Golden Gate 27.0.1: no published CVE entries, 28 Sep 2026) Primary
- CISA — Known Exploited Vulnerabilities catalogue entry for CVE-2026-86950 (added 29 Sep 2026, due 2 Oct 2026) Primary
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog: CVE-2026-86950, added 'based on evidence of active exploitation' (29 Sep 2026) Primary
- CERT-In — Vulnerability Note CIVN-2026-0485: Remote code execution vulnerability in Apple products (1 Oct 2026) Primary
- CERT-In — Vulnerability Note CIVN-2026-0486: Multiple vulnerabilities in Google Chrome for Desktop (1 Oct 2026) Primary
- Google Chrome Releases — Stable Channel Update for Desktop, 154.0.8037.92/.93 (29 Sep 2026) Primary
- Google Chrome Releases — Chrome for Android Update, 154.0.8037.92 (29 Sep 2026) Primary
- Apple Support — Update your iPhone or iPad Primary
- Apple Support — Update macOS on Mac Primary
- Google Chrome Help — Update Google Chrome (computer) Primary
- Google Chrome Help — Update Google Chrome (Android) Primary
- Apple Support — About Lockdown Mode Primary
- Calif — CVE-2026-86950: The Great Glyph Grift (30 Sep 2026) Secondary
- The Hacker News — Apple CoreGraphics PoC emerges as WhatsApp PDF checks hint at possible delivery path (1 Oct 2026) Secondary