Apple released iOS 27.0.1 on September 28, 2026, fixing a bug that made the iPhone 18 Pro and iPhone 18 Pro Max restart whenever Face ID failed to authenticate. The same day, Apple shipped iOS 26.7.1 with a fix for a CoreGraphics flaw it says may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Which update matters more depends on the iOS version on your phone. If you already moved to iOS 27, the first one is your patch. If you are still on iOS 26, the second is the one Apple built for you.
TL;DR: iOS 27.0.1 fixes three bugs, including a Face ID restart on the iPhone 18 Pro and iPhone 18 Pro Max, and Apple lists no CVE entries for it. The urgent security fix is iOS 26.7.1, which patches CVE-2026-86950 in CoreGraphics. Apple says that flaw may have been exploited on iOS versions before iOS 27. Install whichever update matches the iOS version your iPhone runs today.
What iOS 27.0.1 fixes on your iPhone
Apple’s iOS 27 update notes list three fixes in iOS 27.0.1. The first is the one iPhone 18 Pro and iPhone 18 Pro Max owners will recognize, since the phone could restart unexpectedly when Face ID failed to authenticate.
Picture holding your phone up at a store counter and getting a black screen and an Apple logo instead of a payment sheet. After a restart you need your passcode again, so one failed face scan turned into a small chore.
The second fix covers a color artifact that appeared in photos taken at 2x zoom under certain lighting on some iPhone 18 Pro and iPhone 18 Pro Max units. The third addresses a touchscreen that stopped responding when Notification Center and Control Center were opened at the same time.
Apple’s developer releases list puts the build number at 24A446, and its security releases page shows both updates on September 28, 2026, with no published CVE entries for iOS 27.0.1.
| Update | Released | What Apple lists | CVE entries |
|---|---|---|---|
| iOS 27.0.1 | September 28, 2026 | Face ID restart, 2x zoom color artifact, unresponsive touchscreen | None published |
| iOS 26.7.1 | September 28, 2026 | CoreGraphics out-of-bounds write | CVE-2026-86950 |
The bigger story sits one version back.
The iOS 26.7.1 flaw Apple says was exploited
iOS 26.7.1 fixes CVE-2026-86950, an out-of-bounds write in CoreGraphics. Apple’s security notes for iOS 26.7.1 say processing a maliciously crafted file may lead to arbitrary code execution, and they credit Meta Product Security with the report.
Apple also states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. That wording is narrow, and Apple gives no further detail about the attack.
Attacks like this rarely touch most people. Still, the fix covers iPhone 11 and later, so there is little reason to sit on it. Whether you need it comes down to one settings check.
Which update your iPhone should install
Open Settings, tap General, then Software Update, and read the version number at the top. Phones on iOS 27 should take iOS 27.0.1, while iOS 26.7.1 is the release built for phones still on iOS 26.
Plenty of people stay on the older version for a while, and the wide iOS 27 device list shows how many iPhones face that choice. A bug fix and a security fix can share a date and still be meant for different people, which is the detail most coverage of a point release will skip.
What Apple has not said about the exploit
Apple has not said who was targeted, how the malicious file reached them, or whether the attack needed other bugs. Its notes name the flaw, the component, and the reporter, and stop there.
For iOS 27.0.1, the missing CVE entry is worth reading precisely. Apple published no security content for that release, and its notes describe only the three bug fixes above.
If your iPhone 18 Pro has been restarting after a failed Face ID scan, update now. If you are on iOS 26, install iOS 26.7.1 for the security fix and decide separately when to move up to iOS 27.






