Apple on Tuesday pushed a security update for its previous-generation operating systems to address a bug in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs. The vulnerability, tracked as CVE-2026-86950, was discovered by Meta's product security team. According to Apple's security advisory, the bug "may have been exploited" and could be used to launch "an extremely sophisticated attack against specific targeted individuals" on systems running iOS 26.
Details of the exploit have not been released, but the graphics engine typically has broad system access, meaning a successful attack could allow hackers to steal a wide range of personal data. Apple and Meta did not respond to requests for comment about the discovery or the scope of any known attacks. It remains unclear whether the exploit is being used by government spyware makers or cybercriminals.
The company's own statistics show that roughly 80 percent of iPhone users are still running iOS 26, which was superseded earlier this month by iOS 27. The latest OS versions — iOS 27, iPadOS 27 and macOS 27 — also received a software update but are not affected by this particular vulnerability.
A separate zero-click bug now fixed
Apple's latest OS releases also fixed a critical zero-click vulnerability in iMessage, designated CVE-2026-86869. Belgian cybersecurity firm ironPeak published a detailed analysis last week, showing that the bug could be triggered silently via a crafted iMessage without any user interaction. Such zero-click bugs are especially valuable to surveillance vendors. The exploit was capable of bypassing BlastDoor, Apple’s sandbox feature designed to prevent malicious code from escaping the messaging app.
The flaw was reported by ironPeak researcher Niels Hofmans, along with Meta security researchers who confirmed the findings. Apple fixed the bug with the release of iOS 27 in September. It is not yet known if that vulnerability was exploited in the wild.