Key facts
- Apple has fixed a security vulnerability in iOS 26, iPadOS 26, and macOS 26.
- The bug, found in the graphics engine, could allow sophisticated attacks against targeted individuals.
- Meta's product security team discovered the vulnerability.
Apple has released an urgent security update to address a vulnerability in its older operating systems that may have been exploited by hackers. The bug, found in the graphics engine, could allow sophisticated attacks against targeted individuals. Meta's security team discovered the flaw.

A significant number of Apple users remain on older operating systems, making them vulnerable to sophisticated attacks that could compromise personal data. The discovery highlights ongoing risks from advanced spyware and the critical importance of timely software updates.
Apple has issued an urgent security update to address a vulnerability in its iOS 26, iPadOS 26, and macOS 26 operating systems, which the company stated "may have been exploited" by hackers. The bug, located in the core graphics engine responsible for user interface and visuals, could enable highly sophisticated attacks targeting specific individuals on older versions of Apple's software.
Details of the vulnerability, officially designated CVE-2026-86950, have not been fully disclosed. However, a graphics engine typically has extensive access to an operating system, suggesting a successful exploit could lead to the theft of a wide range of personal data. Apple and Meta spokespeople declined to comment on the discovery or the extent of any potential device hacks.
Despite the release of iOS 27, iPadOS 27, and macOS 27 earlier this month, a significant portion of users, nearly 80% of iPhone owners, are still operating on the older iOS 26. These devices, along with those running the latest versions, received a software update on Tuesday, though only the older systems were affected by the newly patched bug.
This patch follows closely behind Apple's fix for another critical security flaw, CVE-2026-86869, a 'zero-click' vulnerability that allowed data theft without user interaction, potentially via a crafted iMessage. This earlier bug could bypass Apple's BlastDoor security feature, designed to protect against spyware. That vulnerability was addressed in September with the release of iOS 27, iPadOS 27, and macOS 27, with credit given to Niels Hofmans of ironPeak and Meta security researchers.
Pick the topics you care about. Get only what matters, on your cadence.