Apple has fixed a security vulnerability in its iOS 26, iPadOS 26 and macOS 26 operating systems that the company says âÂÂmay have been exploitedâ by hackers. The tech giant said the now-fixed bug could be used to launch âÂÂan extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.âÂÂ
According to a listing on AppleâÂÂs security pages, the bug was found in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs.ÃÂ
MetaâÂÂs product security team was credited with the discovery.
Details of the bug, officially classed as CVE-2026-86950, were not released, but a deviceâÂÂs graphics engine typically has broad access to the rest of the deviceâÂÂs operating system. A successful exploit could potentially allow a hacker to steal a broad range of personal data from an affected device.
When reached by TechCrunch, spokespeople for Apple and Meta did not provide comment about how the bug was discovered, or how many people had their devices hacked due to this vulnerability, if any. ItâÂÂs also unclear who may be exploiting the bug, such as government spyware makers or cybercriminals.
While the bug affects AppleâÂÂs previous generation of operating systems, it remains in wide usage. Almost four-in-five of AppleâÂÂs iPhone owners are still running iOS 26, according to the companyâÂÂs own statistics. Devices running the latest version, iOS 27, iPadOS 27, and macOS 27, released earlier this month, also received a software update on Tuesday, but are unaffected by the bug under attack.
A separate âÂÂzero-clickâ bug now fixed
News of the security patch comes soon after Apple fixed another critical security bug, known as CVE-2026-86869, which could have allowed hackers to silently steal data from affected iPhones, iPads, or Macs.ÃÂ
Belgian cybersecurity research firm ironPeak published a detailed writeup last week explaining that the bug was a âÂÂzero-clickâ vulnerability that could be invisibly triggered via a maliciously crafted iMessage, without the userâÂÂs knowledge. Such bugs require no interaction from the victim, such as clicking a link, and are highly sought-after by surveillance vendors and spyware makers.ÃÂ
Per ironPeakâÂÂs post, the bug is capable of bypassing BlastDoor, a security feature that Apple implemented to prevent malicious code, like spyware, from escaping iMessageâÂÂs sandbox and hacking the userâÂÂs device.
Apple fixed the bug in September with the release of iOS 27, iPadOS 27, and macOS 27, and credited ironPeakâÂÂs Niels Hofmans with the discovery, alongside security researchers at Meta who confirmed their findings in a post on X.
ItâÂÂs not yet known if this bug had been used in cyberattacks before it was fixed.
Topics
When you purchase through links in our articles, we may earn a small commission. This doesnâÂÂt affect our editorial independence.
