Still operating on iOS 26? Update your iPhones, iPads, and Macs for this critical security patch.

Still operating on iOS 26? Update your iPhones, iPads, and Macs for this critical security patch.

Apple has addressed a security flaw in its iOS 26, iPadOS 26, and macOS 26 operating systems, which the company indicated “might have been exploited” by malicious actors. The technology leader announced that the rectified issue could have been leveraged to execute “an exceptionally advanced attack against specifically targeted individuals on versions of iOS preceding iOS 27.”

As stated on Apple’s security pages, the flaw was identified within the primary graphics engine that drives the user interface and visuals on iPhones, iPads, and Macs. 

The product security team at Meta received acknowledgment for the detection.

The specifics of the flaw, officially identified as CVE-2026-86950, were not disclosed; however, a device’s graphics engine usually has extensive access to the rest of the device’s operating system. A successful compromise could enable a hacker to expropriate a wide array of personal information from an impacted device.

When contacted by TechCrunch, representatives from Apple and Meta did not comment on how the flaw was discovered, nor on how many users had their devices compromised due to this vulnerability, if any. The identity of potential exploiters, whether state-sponsored spyware developers or cybercriminals, also remains uncertain.

While the flaw influences Apple’s earlier iterations of operating systems, it continues to see widespread use. Nearly 80% of Apple’s iPhone customers are still utilizing iOS 26, as per the company’s own data. Devices operating on the latest version, iOS 27, iPadOS 27, and macOS 27, which were launched earlier this month, also received an update on Tuesday, but are not affected by the vulnerability in question.

Another ‘zero-click’ vulnerability now resolved

The announcement of the security fix arrives shortly after Apple remedied another significant security flaw, designated CVE-2026-86869, which could have permitted hackers to covertly access data from compromised iPhones, iPads, or Macs. 

Last week, Belgian cybersecurity research company ironPeak released a comprehensive report explaining that the flaw was a “zero-click” vulnerability that could be triggered invisibly via a maliciously constructed iMessage, without the knowledge of the user. Such vulnerabilities necessitate no interaction from the victim, such as clicking a link, and are highly coveted by surveillance technology providers and spyware developers. 

According to ironPeak’s publication, the flaw is capable of circumventing BlastDoor, a security feature that Apple introduced to prevent the escape of harmful code, such as spyware, from iMessage’s protected environment and compromising the user’s device.

Apple remedied this flaw in September with the launch of iOS 27, iPadOS 27, and macOS 27, and credited ironPeak’s Niels Hofmans for the discovery, in conjunction with security researchers at Meta who validated their findings in a post on X.

It remains unclear whether this flaw had been utilized in cyberattacks prior to its rectification.

When you make purchases through links in our articles, we may earn a small commission. This does not influence our editorial independence.

Leave a Reply