Apple described CVE-2026-86950 as an out-of-bounds write vulnerability, meaning malicious data could cause software to write information outside the memory area allocated to it. Such memory-corruption bugs can potentially be leveraged to make a device execute attacker-controlled code.
The vulnerability was reported by Meta Product Security, according to Apple. The company fixed it by introducing improved bounds checking.
Why crypto users could be at risk
Blockchain security firm SlowMist has drawn attention to the update because of recent iOS exploitation activity involving cryptocurrency users.
"Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution," SlowMist said.
The firm said the patch was "highly relevant" to the iOS attack activity it had previously been tracking.
"For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data," SlowMist warned.
Importantly, Apple itself has not said that CVE-2026-86950 was specifically used to steal cryptocurrency, nor has SlowMist publicly established that the newly disclosed vulnerability was the exact exploit used in previously investigated wallet thefts.
That warning comes shortly after SlowMist investigated a malicious iOS application called FomoPeek that contained kernel exploits capable of escaping Apple's application sandbox and accessing information belonging to other apps.
According to SlowMist's investigation, malicious versions of FomoPeek were capable of obtaining elevated privileges and potentially accessing Keychain information and files stored by other applications.
The FomoPeek exploit framework reportedly contained multiple attack methods targeting a wide range of iOS releases and was designed to bypass Apple's normal sandbox restrictions.