The Director of Information Security at SlowMist reported that Apple has released iOS/iPadOS 26.7.1, which patches the CVE-2026-86950 vulnerability. According to SlowMist, this vulnerability was actively exploited to steal data from crypto wallets on Apple devices.
Apple confirmed that the vulnerability could have been exploited in "extremely sophisticated attacks targeting specific individuals" on iOS versions prior to 27. The bug allowed writing beyond allocated memory and executing arbitrary code.
SlowMist recommends: update all Apple devices to the latest versions, do not install apps from unverified sources, and do not open suspicious links in Safari or built-in browsers.