# A Targeted iPhone Attack Still Deserves an Ordinary Update

> Apple fixed a file-processing flaw used in a highly targeted attack. Here is the calm response: update every supported iPhone, iPad, and Mac, then reserve Lockdown Mode for people with a real reason to expect personal targeting.

- **Author:** Kubilay Tunca
- **Published:** 2026-09-29
- **Category:** For Mortals
- **Tags:** Apple Security, Online Safety, Software Updates, iPhone
- **Canonical URL:** https://cyber-security-in-plain-english.com/post/mortals/news/targeted-iphone-attack-needs-ordinary-update

---

An iPhone security warning can leave you with two uncomfortable ideas at once. Apple says the attack was aimed at “specific targeted individuals,” which sounds as if the update belongs to somebody else. The same warning says a hostile file could make the device run an attacker’s code, which sounds as if every photo and document now deserves suspicion.

Neither reaction gives you a useful evening. Apple released the repair on 28 September 2026 for supported iPhones, iPads, and Macs. The ordinary response is to use the Software Update screen already on each device, install the newest release offered there, and return once to confirm that the update finished. You do not need to identify a malicious file, buy a scanner, or decide whether you are interesting enough to be a target.

There is a second decision, but it belongs to far fewer people. Apple provides Lockdown Mode for individuals who have a concrete reason to expect a sophisticated, personal attack, such as journalists working with hostile-state sources, dissidents, political campaign staff, or people who have received a genuine threat notification. That setting deliberately breaks or limits some everyday features. A targeted attack makes prompt updating sensible for everyone; it does not make the most restrictive mode sensible for everyone.

## What Apple repaired on 28 September

Apple’s advisory names one flaw, CVE-2026-86950, in a system component called CoreGraphics. The company says that processing a maliciously crafted file could lead to arbitrary code execution, meaning the file could cause the affected process to follow instructions chosen by an attacker. Apple repaired the problem with better bounds checking and credited Meta Product Security with reporting it ([Apple Support: iOS 26.7.1 and iPadOS 26.7.1](https://support.apple.com/en-us/149226)).

CoreGraphics sits behind ordinary visual work. Apps use Apple’s graphics framework to draw and process content, and independent reporting describes images and PDFs as examples of the material that passes through it ([Malwarebytes: Update your iPhone, iPad, or Mac](https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code)). This matters because a dangerous file does not have to arrive with a red warning label. To the person receiving it, it may look like a picture, a document, or another routine item that a device knows how to display.

The fault was an out-of-bounds write. Picture a hotel clerk with a row of numbered key boxes. The clerk should place each key inside the box assigned to it, but a broken measuring rule lets one key push through the back and disturb the box beside it. Computers use boundaries around areas of memory for the same basic reason: one piece of work should not overwrite another piece’s space. A carefully prepared file can exploit a missing check and make software write beyond the area it was given.

A crash is one possible result of memory corruption. A skilled attacker may arrange the surrounding memory so that the bad write changes what the program does next. Apple’s impact statement allows the serious possibility of arbitrary code execution, but it does not publish the complete attack chain, the delivery route, or the further steps an attacker may have needed after the first piece of code ran. As of 29 September 2026, claims about a particular messaging app, a named spyware vendor, cryptocurrency wallets, or a mass campaign go beyond Apple’s public account.

Apple’s exploitation language is precise. The company is aware of a report that the issue **may have been exploited** in an “extremely sophisticated attack” against “specific targeted individuals” using versions of iOS before iOS 27. The Hacker News independently confirmed the advisory and noted that Apple had not said how many people were targeted, whether the attempts succeeded, or when the first attempt occurred ([The Hacker News: Apple patches CoreGraphics flaw](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html)). Those unknowns deserve to remain unknown rather than being filled with dramatic guesses.

The confirmed repair list is much clearer. Apple shipped iOS 26.7.1 and iPadOS 26.7.1 for iPhone 11 and later, iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later. It also shipped macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 ([Apple Support: iOS and iPadOS](https://support.apple.com/en-us/149226); [Apple Support: macOS Tahoe](https://support.apple.com/en-us/149228); [Apple Support: macOS Sequoia](https://support.apple.com/en-us/149229)).

That list is a dated baseline, not a number to force onto every Apple device. Your phone may offer iOS 27, your Mac may be on another current branch, and later releases will replace today’s numbers. The reliable instruction is to open the built-in Software Update screen on the device in your hand and install the current update Apple offers for that model and branch. The advisory tells us why to act; the device tells us which package belongs to it.

## “Targeted” describes the campaign, not the value of the patch

People hear “specific targeted individuals” and reasonably ask whether the story matters to a normal household. It helps to separate the attacker’s first campaign from the life of the flaw after publication. Apple’s wording says the observed activity was narrow and sophisticated. It does not say that the faulty code exists only on the victims’ phones.

Before a repair becomes public, a working technique may be scarce. An attacker who spent money or time developing it has a reason to save it for people whose messages, contacts, location, or work justify that cost. Once the vendor ships a fix and names the faulty component, other researchers can compare old and new code, study the change, and learn more about the weak spot. That does not guarantee a wave of attacks, but it changes the economics of leaving an affected device behind.

Think of a locksmith repairing an unusual fault in one model of door. The first burglar may have discovered the fault while pursuing one particular house. Once the repair is public, every owner of that door has a cheap choice: fit the improved part or keep relying on the burglar’s discretion. Prompt updating is the cheap part. You do not need evidence that your house was on the original list before replacing the faulty piece.

This is why the same facts support different actions for different people. Everyone with a supported affected device should install the ordinary software update because the cost is small and the faulty code is shared. A reporter investigating a government, a human-rights worker under surveillance, or an executive handling a sensitive negotiation may add stricter controls because the consequence and likelihood of personal targeting are different. The patch threshold is low; the life-disrupting protection threshold is higher.

The distinction also prevents panic. Targeted exploitation is not evidence that every iPhone was compromised before breakfast. Apple has not reported a broad campaign, and The Hacker News says the public record lacks a victim count or success rate. If your device is working normally and you have no separate warning, the headline alone does not justify wiping it, changing every password, or treating each old photo as hostile.

Updating cannot prove that a device was never touched before the repair. It closes the published weakness for the fixed software going forward. That limit matters most to people who have received a specific warning or have a credible reason to expect surveillance. They may need expert help preserving evidence and reviewing accounts. For the rest of us, turning a narrow report into a universal forensic investigation would create much more work than the evidence supports.

The calm middle has a firm recommendation. Install the update today, while the reason is fresh. Then stop unless another piece of evidence gives you a reason to continue.

## How one ordinary file can reach system code

A phone appears to have tidy borders between apps. Messages lives in one icon, Photos in another, Mail in a third, and Safari in a fourth. Under those icons, the operating system supplies shared components so every developer does not have to write a new image renderer, font engine, or drawing system from scratch. CoreGraphics is part of that shared machinery.

Shared machinery brings a real benefit. Apple can repair one component and deliver the fix through an operating-system update rather than waiting for every app maker to invent a separate correction. It also means a fault in a common parser may be reachable from more than one visible app. The important boundary is the code that interprets the file, not the logo you tapped before the file appeared.

Suppose a family group receives a photo from an unfamiliar number. One person views it in Messages. Another saves it and opens it from Photos. A third receives the same material inside a document. Those routes can look different to the humans while eventually asking shared system code to decode visual content. This example explains the shape of the risk; Apple has not publicly named the delivery route used in the reported attack.

“Processing” can also happen before a person deliberately opens a file. Modern devices create thumbnails, previews, notifications, search indexes, and metadata so the screen feels immediate. Whether this particular attack worked through any such automatic path has not been disclosed. The useful lesson is narrower: advice that says “just do not open suspicious files” cannot repair a flaw in the software responsible for deciding what a file contains.

File caution still has value. An unexpected attachment from a stranger deserves less trust than a family picture you asked for. A request that creates urgency, secrecy, or a demand to install a profile should trigger a pause. Yet appearance and sender familiarity cannot certify the bytes inside a file, especially if an account has been taken over. The operating system’s memory checks are supposed to provide protection even when human judgement has little to work with.

The update improves one of those checks. Apple says it addressed the issue with improved bounds checking, the digital equivalent of making the clerk verify the box size before placing anything inside. That repair happens below the level where a user can compensate with careful tapping. No browser setting, antivirus subscription, or habit of deleting old messages can add the missing check to CoreGraphics.

This is also why third-party “cleaner” apps are a distraction. An app can scan files it is allowed to reach, remove clutter, or recognise known bad patterns. It cannot replace the protected operating-system component with Apple’s corrected version. The code repair comes from Apple’s signed update channel. Go to Settings or System Settings, not to an advert promising to inspect the phone for CVE numbers.

## The update has three states

“Apple released a fix” describes Apple’s side of the transaction. Your device still has to receive, install, and begin running it. Those stages often collapse into one word, so a person sees a download complete and reasonably believes the whole job is over.

The first state is **available**. Apple has published a package for a supported device and branch. The second is **downloaded or preparing**. Files may be on the device while it checks space, power, and other conditions. The third is **installed and running**, which normally follows the restart or installation sequence and appears as the current version on the Software Update screen.

Automatic Updates can bridge much of that gap. Apple says an iPhone can download and install an available update overnight while it is charging and connected to Wi-Fi, with a notification before installation. The same settings page lets a person enable automatic installation and automatic system-file updates ([Apple Support: Update your iPhone or iPad](https://support.apple.com/en-us/118575)). This is worth turning on because it converts many future repairs into background maintenance.

Automatic does not mean instantaneous. A phone may spend the night away from power, use a network that cannot reach the update service, lack enough free space, or wait for a passcode and agreement. Apple’s update guide also notes that a VPN or proxy can prevent contact with update servers, and that some updates may temporarily remove apps to make space before restoring them. A setting can be correct while the latest installation remains unfinished.

The receipt is simple. After the device restarts, open **Settings**, choose **General**, then **Software Update**. The page shows the installed iOS version and whether another update is available. On a Mac, open the Apple menu, choose **System Settings**, then **General** and **Software Update**. Let the check finish rather than leaving when the spinner first appears.

Do not become trapped by today’s exact branch number. If an iPhone on iOS 26 shows 26.7.1 installed, that matches Apple’s 28 September repair. If a compatible phone offers a current iOS 27 release instead, follow the supported path shown by Software Update. If you read this later and see a higher current release, moving forward is expected. Security maintenance is a path, not a scavenger hunt for an old package.

A screenshot of the final screen can help when you maintain a parent’s device or a few company phones. It should show the date, model or device name if appropriate, current version, and update status. Avoid collecting message previews, Apple Account details, or anything else unrelated. The receipt should settle the maintenance question without creating a new bundle of private information.

## A ten-minute check for every Apple device you use

Choose a time when each device can restart. Save a draft message, finish a payment, and make sure irreplaceable photos or work exist in a current backup. Apple recommends backing up before a wireless iPhone or iPad update, then connecting the device to power and Wi-Fi ([Apple Support: Update your iPhone or iPad](https://support.apple.com/en-us/118575)). This preparation is ordinary care, not evidence that the patch is likely to fail.

1. **Start inside the device.** On an iPhone or iPad, open **Settings**, **General**, then **Software Update**. On a Mac, open **System Settings**, **General**, then **Software Update**. Ignore update links in text messages, email, search adverts, and pop-ups.

2. **Read the installed state.** Note the version currently shown and let the device complete its check. An iPhone or iPad still on the iOS or iPadOS 26 branch should receive 26.7.1 if its model is in Apple’s supported list. A Mac on Tahoe should receive 26.7.1, while one on Sequoia should receive 15.8.1. A current later branch may show a different version.

3. **Install the newest supported update offered.** Tap or click the built-in download and install control. Keep a mobile device connected to power and Wi-Fi. Keep a Mac powered and online. Enter the device passcode or administrator password only in the operating system’s own prompt.

4. **Allow the restart to finish.** A dark screen, progress bar, and more than one restart can be normal. Do not force the device off because the progress pauses briefly. If it shows an error, photograph the exact message before trying random fixes.

5. **Return for the receipt.** Open Software Update again after signing in. Confirm the installed version and let the page check once more. If another small update appears, install that too. The second visit proves more than remembering that a progress bar appeared.

6. **Turn on future automatic updates.** On iPhone or iPad, the path is **Settings**, **General**, **Software Update**, **Automatic Updates**. Apple says automatic installation occurs overnight when the phone is charging and on Wi-Fi. Leave the system-file update option enabled as well unless a device administrator has given you a specific reason not to.

7. **Repeat on the devices people forget.** The daily phone comes first, then the iPad on the kitchen counter, the MacBook that usually sleeps, and the older spare used for travel. A device switched off in a drawer cannot process a hostile file, but update it before returning it to normal use.

8. **Stop when the supported devices are current.** You do not need to run an exploit test, inspect CoreGraphics, or upload private files to an online scanner. A completed built-in update with no remaining offer is the ordinary household finish line.

For a family, one person can help without taking over everybody’s accounts. Sit beside the owner, point to the Software Update screen, and let them enter their own passcode. If you are helping remotely, ask for a photograph of that screen after the restart. “It updated last night” is understandable; the version page is clearer.

For a small business with a handful of Apple devices, use a modest list: device, regular user, current branch, check date, result, and any error sent to support. The value lies in finding the reception iPad or spare Mac that nobody remembered. A five-device shop does not need a glossy security dashboard to notice the one device still waiting.

## Decide about Lockdown Mode separately

Apple uses unusually strong language for both the reported attack and Lockdown Mode, which makes it tempting to connect them automatically. Resist that shortcut. Updating repairs known faulty code with little effect on daily life. Lockdown Mode changes how the device behaves because it reduces the number and complexity of routes that a sophisticated attacker might use.

Apple describes Lockdown Mode as optional, extreme protection for the very few people who may be personally targeted because of who they are or what they do. The company says most people are never targeted by attacks of that nature ([Apple Support: About Lockdown Mode](https://support.apple.com/en-us/105120)). This language calibrates the threat without dismissing it. It explains the cost and intended audience of the control.

The costs are concrete. Apple says Lockdown Mode blocks most message attachment types apart from certain images, video, and audio; removes some links and link previews; limits complex web technologies; restricts incoming FaceTime calls from people you have not called recently; blocks some service invitations; and tightens device connections. Some websites may load slowly or fail, and some everyday features may be unavailable. The restrictions are the mechanism, not an accidental inconvenience.

A person with a credible personal threat may find that trade worthwhile. Examples can include a journalist receiving state-linked threats, an activist whose colleagues have been infected with mercenary spyware, a lawyer on a sensitive cross-border case, a political figure during a hostile campaign, or somebody who has received an authentic Apple threat notification. Job title alone cannot decide it, but a specific adversary, sensitive access, prior targeting, and expert advice can.

Most households should install the update and leave Lockdown Mode off. Turning it on because a headline used the word “sophisticated” can break websites and communication features without addressing a threat you are likely to face. Worse, the resulting friction may teach the family to disable security settings whenever they become inconvenient. Controls work best when their cost matches the risk.

If your situation does justify it, update first. Apple explicitly recommends installing the latest software before enabling Lockdown Mode. On iPhone or iPad, the path is **Settings**, **Privacy & Security**, then **Lockdown Mode**. The device restarts after activation. Apple says it must be enabled separately on iPhone, iPad, and Mac, although a paired Apple Watch follows the iPhone setting ([Apple Support: About Lockdown Mode](https://support.apple.com/en-us/105120)).

Do not exclude a website, app, or contact merely to make the warnings disappear. Apple says an exclusion reduces the protection for that item. Make the exception only when the service is trusted, the need is real, and you understand which restriction you are lifting. Someone under serious threat should ideally review exceptions with a security professional who understands their work rather than with a stranger in a forum.

The decision can be revisited. A period of heightened risk may justify stricter settings during travel, reporting, litigation, or an election. When the situation changes, review the control instead of leaving a badly understood configuration forever. Security should fit the person’s actual life and adversary.

## What the update does not prove

A successful update proves that the device reached a newer software state. It does not reconstruct everything that happened before installation. If Apple’s published flaw was used against a device last week, applying the repair today cannot remove the historical fact or guarantee that no other component was changed.

That limitation should guide escalation rather than frighten everyone. A person who received an authentic threat notification, found an unfamiliar management profile, saw repeated unexplained Apple Account sign-ins, or has a credible reason to expect a named adversary should preserve those details and seek qualified help. The evidence creates the larger task. The existence of CVE-2026-86950 by itself does not.

Be careful with supposed evidence delivered by a caller or pop-up. Scammers borrow current security stories because urgency makes an instruction feel official. Apple’s repair does not require a stranger to connect to your screen, your recovery key to be read aloud, or cryptocurrency to be moved for safekeeping. If somebody contacts you about the flaw, end the conversation and open Software Update yourself.

An unexpected Apple Account sign-in deserves an account response. Use a separate trusted device if necessary, review devices signed into the account, remove ones you do not recognise, change the password through Apple’s official settings, and make sure two-factor authentication and trusted contact details remain yours. Those steps respond to account evidence. Repeating the operating-system update will not remove an intruder who already controls the account.

An unfamiliar configuration or management profile deserves similar care because profiles can alter network, certificate, and device-management behaviour. Do not delete evidence in a hurry if you are a high-risk target seeking forensic help. A normal home user who knowingly installed a work or school profile should expect to see it. Context turns the same screen from ordinary administration into a question.

A battery draining quickly, a warm phone, or one app crashing is weak evidence by itself. Updates trigger indexing, photo analysis, and background work that can temporarily use more power. Everyday software also fails for boring reasons. Record a persistent pattern and ask Apple Support or a trusted technician to examine it, but do not let a generic symptom plus a zero-day headline become a confident diagnosis.

The repair also does not make every future file safe. It closes this published weakness on the fixed branches. Good update habits, sensible attachment caution, account protection, and backups still matter because software will have other faults and scams often avoid technical exploits entirely. One repaired lock is valuable even though the house contains more than one door.

## What does not earn your time

Searching old messages for a file that “looks hacked” is unlikely to tell you anything reliable. Apple has not published the file format, visual appearance, sender, or delivery app used in the reported attack. A malicious file can look ordinary, and an ugly file can be harmless. Let the code update do the work that appearance cannot.

Deleting all photos and PDFs would cause real loss without adding the repaired memory check. The device still needs the fixed CoreGraphics code for future content, websites, previews, and files. Back up what matters, update the operating system, and keep your family archive.

Changing every password is also the wrong opening move when the only evidence is this advisory. Apple has not said that CVE-2026-86950 broadly stole passwords. Fresh passwords entered on an unpatched device do not repair CoreGraphics. Update first, then change credentials only when an account alert, reused password, authentic breach notice, or other evidence gives you a reason.

A factory reset is a costly response to a repair that Apple already supplies through Software Update. Resetting removes data and settings, may leave a person struggling to recover accounts, and still requires installing current software afterwards. Reserve a rebuild for a device with evidence of compromise or advice from somebody qualified to examine the case.

Third-party scanners cannot certify that an iPhone was never targeted. Mobile operating systems deliberately restrict what ordinary apps can inspect. A product may block known malicious sites or scam messages, but a large green checkmark cannot substitute for Apple’s patch or a specialist forensic review when personal targeting is credible.

You can also ignore arguments about whether the story deserves the label “zero-day.” The useful facts are settled enough: Apple repaired CVE-2026-86950 on 28 September, said a report linked it to a sophisticated targeted attack, and published fixed versions for supported devices. Vocabulary will not move your phone across the update line.

The number to remember is not the CVE. Remember the route: **Settings, General, Software Update, install, return to check.** On a Mac: **System Settings, General, Software Update, install, return to check.**

## Keep the response smaller than the headline

This story contains a serious technical possibility and a reassuring practical answer. A crafted file could make affected system code run attacker-chosen instructions. Apple’s public account links the flaw to a sophisticated attack against particular people, not to a broad sweep of every customer. The repair is available through the normal update channel.

That combination is common in personal security. You rarely get certainty about every past event, but you often get a clear next action. The best response closes the known route, records the result, and leaves room for a larger investigation only when evidence calls for one.

Make the update boring. Put the phone on charge, use Wi-Fi, open the built-in page, and let it restart. Check the iPad that lives on the sofa and the Mac that spends most nights asleep. Turn on automatic updates so the next repair has fewer chances to wait behind an ordinary week.

Then use the targeting information for calibration. Most people can stop at the successful update screen. People with a credible personal threat can add Lockdown Mode and expert help, accepting the limits because the extra protection buys something their situation needs. Everybody else has permission to skip the extreme setting.

The Digital Fortress makes the same bargain throughout: spend your patience on a small number of controls that close real doors, then get back to your life. Today, Software Update is that door. You do not need to become a CoreGraphics expert to lock it.

For calm, practical security guidance, join the Cyber Security in Plain English newsletter. One email per month, with no daily alarm bell.

## Sources

- [Apple Support: About the security content of iOS 26.7.1 and iPadOS 26.7.1](https://support.apple.com/en-us/149226), accessed 2026-09-29
- [Apple Support: About the security content of macOS Tahoe 26.7.1](https://support.apple.com/en-us/149228), accessed 2026-09-29
- [Apple Support: About the security content of macOS Sequoia 15.8.1](https://support.apple.com/en-us/149229), accessed 2026-09-29
- [The Hacker News: Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html), accessed 2026-09-29
- [Malwarebytes: Update your iPhone, iPad, or Mac: Flaw could run attackers’ code](https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code), accessed 2026-09-29
- [MacRumors: iOS 26.7.1 Fixes Vulnerability Used in Targeted Attacks](https://www.macrumors.com/2026/09/28/ios-26-7-1-active-exploit-fixed/), accessed 2026-09-29
- [Apple Support: Update your iPhone or iPad](https://support.apple.com/en-us/118575), accessed 2026-09-29
- [Apple Support: About Lockdown Mode](https://support.apple.com/en-us/105120), accessed 2026-09-29

---

## About the author

Kubilay Tunca — Senior Full Stack Developer and Author. Founded Cyber Security in Plain English to translate complex security concepts into clear, practical advice, and writes the accompanying books on security, privacy, secure development, and AI systems.

## Books by this author

- **The Digital Fortress** — Your Everyday Guide to a Safer Digital Life. A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest. [Amazon](https://buy.cyber-security-in-plain-english.com/digital-fortress) · [Details](https://cyber-security-in-plain-english.com/books/the-digital-fortress)
- **The Anonymity Playbook** — Digital Survival for Whistleblowers, Journalists, Activists, and Everyone Else. A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails. [Amazon](https://buy.cyber-security-in-plain-english.com/anonymity-playbook) · [Details](https://cyber-security-in-plain-english.com/books/the-anonymity-playbook)
- **Secure Software Development** — Practical patterns for building secure software. A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-software-development) · [Details](https://cyber-security-in-plain-english.com/books/secure-software-development)
- **The Secure Harness** — Shipping Production Code with AI Coding Agents. A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-harness) · [Details](https://cyber-security-in-plain-english.com/books/the-secure-harness)
- **The AI Native Engineer** — Build, Evaluate, and Ship AI Systems That Work in Production. Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature. [Amazon](https://buy.cyber-security-in-plain-english.com/ai-native-engineer) · [Details](https://cyber-security-in-plain-english.com/books/the-ai-native-engineer)

Full catalogue with contents and intended audience: https://cyber-security-in-plain-english.com/books

_As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog._
