Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix
Key Points:
- Apple has fixed a security vulnerability (CVE-2026-86950) in iOS 26, iPadOS 26, and macOS 26 that could have been exploited for sophisticated attacks targeting individuals, affecting the main graphics engine of these devices.
- The vulnerability was discovered by Meta’s product security team, but details about the bug’s exploitation or affected users remain undisclosed by both Apple and Meta.
- Despite the bug affecting previous OS versions, nearly 80% of iPhone users still run iOS 26, making the patch critical, while devices on the latest OS versions (iOS 27, iPadOS 27, macOS 27) are unaffected.
- Recently, Apple also fixed another critical "zero-click" vulnerability (CVE-2026-86869) discovered by Belgian firm ironPeak, which could be triggered via a malicious iMessage without user interaction and bypasses Apple’s BlastDoor security feature.
- Both vulnerabilities highlight ongoing threats from advanced spyware and surveillance tools, though it is unclear if either bug was exploited in real-world attacks before being patched.