Apple Patches Possibly Exploited iOS 26 Flaw Affecting iPhones, iPads and Macs
Apple patches a possibly exploited graphics flaw in iOS 26, iPadOS 26 and macOS 26, while a separate zero-click iMessage bug raises serious spyware fears.
Summary
Apple on Tuesday, September 29, 2026, patched CVE-2026-86950 in iOS 26, iPadOS 26 and macOS 26. Apple says hackers may have exploited the graphics engine flaw in an extremely sophisticated attack against specific individuals using iOS versions before iOS 27. The engine powers device interfaces and visuals, and its broad operating system access could potentially expose personal data. Meta’s product security team discovered the vulnerability, but technical details remain undisclosed.
Almost four in five iPhone owners still use iOS 26. iOS 27, iPadOS 27 and macOS 27, released earlier in September, also received Tuesday updates but are unaffected by the attacked flaw. Apple and Meta have not disclosed how it was discovered, who exploited it, or how many devices were compromised, if any. It remains unclear whether government spyware operators or cybercriminals were involved.
The patches follow September’s fix for CVE-2026-86869, a zero-click flaw that ironPeak said could silently steal data through a malicious iMessage without user interaction. It could bypass BlastDoor, Apple’s safeguard against code escaping the iMessage sandbox. Apple credited ironPeak researcher Niels Hofmans, while Meta researchers confirmed the findings on X. Whether attackers exploited CVE-2026-86869 remains unknown.
Positives
- Apple patched CVE-2026-86950 across iOS 26, iPadOS 26 and macOS 26 on September 29, 2026.
- iOS 27, iPadOS 27 and macOS 27 are unaffected by the graphics flaw under attack and received additional Tuesday updates.
- Meta’s product security team discovered CVE-2026-86950, enabling Apple to close the potentially exploited vulnerability.
- September’s operating system releases fixed CVE-2026-86869 after work by ironPeak’s Niels Hofmans and Meta researchers.
Risks & concerns
- Apple says CVE-2026-86950 may have enabled extremely sophisticated attacks against specific individuals running iOS versions before iOS 27.
- Almost four in five iPhone owners remain on iOS 26, leaving a widely used operating system dependent on prompt patch installation.
- CVE-2026-86950 affects a graphics engine with broad operating system access, potentially exposing extensive personal data.
- CVE-2026-86869 could silently steal data through a malicious iMessage and bypass Apple’s BlastDoor protection without requiring user interaction.
- Apple and Meta have not disclosed the attackers, discovery circumstances or number of compromised devices, and exploitation of CVE-2026-86869 remains unknown.