Crypto iconCryptoSep 29, 2026 ~7 min source read

Apple fixes CoreGraphics zero-day; what iPhone users with crypto wallets need to know

Apple released iOS 26.7.1 and related fixes for a CoreGraphics flaw (CVE-2026-86950) that could run attacker code. Blockchain security firms warn crypto holders to update and take specific cleanup steps if they used risky apps.

Apple patches iOS vulnerability, are crypto wallets still at risk?

Share this story

Send the public story page.

Useful takeaways from this story.

The flaw is an out-of-bounds write in CoreGraphics that can enable arbitrary code execution when a device processes a maliciously crafted file.

SlowMist warned the patch is especially relevant for crypto users because recent iOS exploits have targeted wallet data, though there’s no public proof this CVE powered specific wallet thefts.

If you installed known malicious apps such as risky FomoPeek versions, remove them, update the OS, and consider creating new wallets on clean devices and moving funds.

# What happened Apple released security updates on Sept. 28 that fix a CoreGraphics vulnerability tracked as CVE-2026-86950. The company says processing a maliciously crafted file could trigger an out-of-bounds write and allow arbitrary code execution. Meta Product Security reported the issue and Apple implemented improved bounds checking to address it.

# Why crypto users are watching Blockchain security firm SlowMist flagged the patch because recent iOS exploitation activity has targeted sensitive wallet information. SlowMist did not publicly demonstrate that CVE-2026-86950 was the specific vulnerability behind documented wallet compromises, but the timing and nature of the fix prompted warnings for self-custody users.

# What Apple disclosed Apple's advisory states the vulnerability may have been exploited in an "extremely sophisticated attack" against specific targeted individuals using iOS versions released before iOS 27. The company did not name targets, delivery method, or file format used in the known attacks, and it did not attribute exploitation to any group or vendor.

# Devices affected The advisory covers iPhone 11 and later models still running the iOS 26 branch and supported iPad Pro, iPad Air, iPad, and iPad mini models on iPadOS 26. Apple also patched the same CoreGraphics issue in macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.

# How this relates to other crypto-targeting incidents

# Practical actions for crypto wallet users

  • Update immediately: Apply iOS 26.7.1 or iPadOS 26.7.1 (or the latest iOS 27.x releases where applicable) and install the macOS fixes if you use a Mac.
  • If you suspect compromise: Create a new wallet on a device that has never had the risky app installed and move funds there. Change relevant credentials stored in the device Keychain.
  • Monitor activity: Watch wallet balances, transaction histories, and any account activity tied to your crypto holdings.

# What remains uncertain Apple acknowledged possible targeted exploitation before public disclosure but did not confirm the identities of targets, the exact delivery vector, or whether the flaw directly led to confirmed cryptocurrency thefts. SlowMist's warning links the patch to recent wallet-targeting activity but stops short of naming this CVE as the proven cause of prior incidents.

# Bottom line Apply Apple's security updates without delay. If you used apps or app versions that security researchers have flagged for wallet-targeting behavior, treat those devices as potentially compromised, migrate private keys to a clean device, and remove the risky software.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app