Apple patches actively exploited graphics-engine flaw in iOS 26, iPadOS 26, macOS 26
Apple has released a security update fixing a vulnerability in the graphics engine underlying iOS 26, iPadOS 26 and macOS 26, which the company says may have already been used against specific targeted individuals. Meta's product security team discovered and reported the flaw, tracked as CVE-2026-86950; Apple did not disclose how it was found or how many devices were affected. Devices on the newer iOS 27, iPadOS 27 and macOS 27 also received Tuesday's update but were not vulnerable to this particular bug.
GoKawiil's interpretation of the reporting above, not reported fact.
Because a device's graphics engine typically has deep access across the operating system, a successful exploit could let an attacker pull a wide range of personal data from a compromised phone or computer. With roughly four in five iPhone users still on iOS 26, the exposure window could be large even though Apple describes the attack as narrowly targeted; who is behind it, whether spyware vendors or criminal hackers, remains unknown. The disclosure follows a separate zero-click flaw fixed last week, suggesting Apple's older OS generation has faced a cluster of serious security issues recently.
- Apple fixed CVE-2026-86950, a graphics-engine bug in iOS 26, iPadOS 26 and macOS 26 that may have been exploited against targeted individuals.
- Meta's product security team discovered and reported the vulnerability; Apple has not shared details on how it was found or exploited.
- About 80% of iPhone users still run iOS 26, meaning many devices were exposed before Tuesday's patch.
Source: techcrunch.com — Zack Whittaker, 2026-09-29
Published there as: “Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.