Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix
Apple patched graphics-engine CVE-2026-86950 in iOS 26 after possible targeted exploitation.
Apple patched CVE-2026-86950 in iOS 26, iPadOS 26, and macOS 26 after saying it may have been exploited in extremely sophisticated attacks against specific people. The flaw is in the graphics engine that draws the interface; a successful exploit could expose a broad range of personal data. Apple says roughly four in five iPhones still run iOS 26, while iOS 27, iPadOS 27, and macOS 27 are unaffected. A separate zero-click bug, CVE-2026-86869, fixed with those 27 releases, could be triggered by a malicious iMessage and bypass BlastDoor; use before the fix is not confirmed.
- CVE-2026-86950 is in the graphics engine on iOS 26, iPadOS 26, and macOS 26.
- Apple says it may have been used in sophisticated attacks on specific people.
- About four in five iPhones still run iOS 26; iOS 27 is unaffected.
- Separate zero-click CVE-2026-86869 abused iMessage and bypassed BlastDoor.
- Meta found the graphics bug; ironPeak and Meta reported the iMessage issue.
Vulnerabilities mentionedAll →
- CVE-2026-868696.5—Out-of-bounds write in Apple image handling crashes appspublished · Apple iOS
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
Full article504 words · extracted from techcrunch.com · click to collapse
Apple has fixed a security vulnerability in its iOS 26, iPadOS 26 and macOS 26 operating systems that the company says “may have been exploited” by hackers. The tech giant said the now-fixed bug could be used to launch “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
According to a listing on Apple’s security pages, the bug was found in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs.
Meta’s product security team was credited with the discovery.
Details of the bug, officially classed as CVE-2026-86950, were not released, but a device’s graphics engine typically has broad access to the rest of the device’s operating system. A successful exploit could potentially allow a hacker to steal a broad range of personal data from an affected device.
When reached by TechCrunch, spokespeople for Apple and Meta did not provide comment about how the bug was discovered, or how many people had their devices hacked due to this vulnerability, if any. It’s also unclear who may be exploiting the bug, such as government spyware makers or cybercriminals.
While the bug affects Apple’s previous generation of operating systems, it remains in wide usage. Almost four-in-five of Apple’s iPhone owners are still running iOS 26, according to the company’s own statistics. Devices running the latest version, iOS 27, iPadOS 27, and macOS 27, released earlier this month, also received a software update on Tuesday, but are unaffected by the bug under attack.
A separate ‘zero-click’ bug now fixed
News of the security patch comes soon after Apple fixed another critical security bug, known as CVE-2026-86869, which could have allowed hackers to silently steal data from affected iPhones, iPads, or Macs.
Belgian cybersecurity research firm ironPeak published a detailed writeup last week explaining that the bug was a “zero-click” vulnerability that could be invisibly triggered via a maliciously crafted iMessage, without the user’s knowledge. Such bugs require no interaction from the victim, such as clicking a link, and are highly sought-after by surveillance vendors and spyware makers.
Per ironPeak’s post, the bug is capable of bypassing BlastDoor, a security feature that Apple implemented to prevent malicious code, like spyware, from escaping iMessage’s sandbox and hacking the user’s device.
Apple fixed the bug in September with the release of iOS 27, iPadOS 27, and macOS 27, and credited ironPeak’s Niels Hofmans with the discovery, alongside security researchers at Meta who confirmed their findings in a post on X.
It’s not yet known if this bug had been used in cyberattacks before it was fixed.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.