Apple patches critical graphics engine bug exploited in targeted attacks; separate zero-click iMessage flaw also fixed

Urgent updates issued for iOS 26, iPadOS 26 and macOS 26 as researchers detail a second vulnerability that bypassed BlastDoor security

By LineZotpaper
Published
Read Time2 min
Apple has released security updates for iOS 26, iPadOS 26 and macOS 26 to patch a vulnerability in the graphics engine that the company says may have been exploited in sophisticated targeted attacks. Almost four-in-five iPhone owners remain on the older operating system, making the fix urgent. Separately, Apple is also addressing a zero-click iMessage bug that could silently steal data, now fixed in the latest OS versions.

Apple on Tuesday pushed a security update for its previous-generation operating systems to address a bug in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs. The vulnerability, tracked as CVE-2026-86950, was discovered by Meta's product security team. According to Apple's security advisory, the bug "may have been exploited" and could be used to launch "an extremely sophisticated attack against specific targeted individuals" on systems running iOS 26.

Details of the exploit have not been released, but the graphics engine typically has broad system access, meaning a successful attack could allow hackers to steal a wide range of personal data. Apple and Meta did not respond to requests for comment about the discovery or the scope of any known attacks. It remains unclear whether the exploit is being used by government spyware makers or cybercriminals.

The company's own statistics show that roughly 80 percent of iPhone users are still running iOS 26, which was superseded earlier this month by iOS 27. The latest OS versions — iOS 27, iPadOS 27 and macOS 27 — also received a software update but are not affected by this particular vulnerability.

A separate zero-click bug now fixed

Apple's latest OS releases also fixed a critical zero-click vulnerability in iMessage, designated CVE-2026-86869. Belgian cybersecurity firm ironPeak published a detailed analysis last week, showing that the bug could be triggered silently via a crafted iMessage without any user interaction. Such zero-click bugs are especially valuable to surveillance vendors. The exploit was capable of bypassing BlastDoor, Apple’s sandbox feature designed to prevent malicious code from escaping the messaging app.

The flaw was reported by ironPeak researcher Niels Hofmans, along with Meta security researchers who confirmed the findings. Apple fixed the bug with the release of iOS 27 in September. It is not yet known if that vulnerability was exploited in the wild.

§

Analysis

Why This Matters

  • Users still on iOS 26 are exposed to a graphics engine bug that Apple confirms has been exploited in targeted attacks, potentially enabling broad data theft.
  • The separate zero-click iMessage vulnerability bypassed Apple's Blastdoor protection, highlighting that even advanced sandboxing can be defeated.
  • With the majority of iPhone users yet to upgrade, a large installed base remains vulnerable until they apply the patch.

Background

Apple regularly issues security updates for older operating systems when critical flaws are discovered. The graphics engine bug is notable because Apple acknowledged exploitation, though limited to targeted individuals. Zero-click exploits are among the most dangerous in mobile security because they require no victim interaction. Apple introduced BlastDoor in 2021 to harden iMessage against such attacks, but ironPeak's research demonstrates that determined researchers could still find ways around it.

Key Perspectives

Apple: The company has acted quickly to patch both vulnerabilities, releasing updates for the previous OS generation and crediting external researchers. Apple has not provided details on the attackers or the number of victims. Meta's security team: Meta was credited for discovering the graphics engine bug and collaborated with ironPeak on the iMessage flaw, reflecting the company's ongoing investment in platform security research. ironPeak (Niels Hofmans): The Belgian researcher disclosed the zero-click bug responsibly and published technical details after Apple issued a fix, providing transparency to the security community. Users: Those on iOS 26 or earlier should update immediately. Users on iOS 27 are not affected by either vulnerability but have received a software update that Apple recommends.

What to Watch

  • Whether Apple releases more technical details on the exploitation of the graphics engine bug if investigations proceed.
  • Adoption rates of iOS 27: as p date usage figures will show how quickly users respond to this security notice.
  • Potential emergence of similar zero-click iMessage bugs: ironPeak's findings may prompt other researchers to examine iMessage's code paths.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.