Apple fixes iOS 26 vulnerability that could have been used for attacks — TechCrunch
Apple has released security updates for iOS 26, iPadOS 26 and macOS 26, fixing a vulnerability that, according to the company, could have been used by hackers for highly sophisticated attacks against specific targeted users of system versions prior to iOS 27. As TechCrunch reports, the issue is identified as CVE-2026-86950.
The vulnerability was found in the main graphics engine responsible for the interface and visual elements on iPhone, iPad and Mac. Apple credited Meta’s product security team for discovering it. The company did not disclose technical details of the flaw.
Risk for devices running older systems
The graphics engine has broad access to the device’s operating system, so successful exploitation of this vulnerability could potentially have allowed attackers to steal a significant amount of personal data. Apple and Meta did not comment on how the issue was discovered or how many devices may have been compromised through it, if such cases occurred.
More current news is available on the UA.News Telegram channel Telegram.
According to Apple’s statistics, nearly four out of five iPhone owners continue to use iOS 26. Devices running iOS 27, iPadOS 27 and macOS 27, released earlier this month, also received updates, but they are not affected by this vulnerability.
Another critical flaw in iMessage
Earlier, Apple also fixed the critical vulnerability CVE-2026-86869, which could have allowed data to be secretly stolen from an iPhone, iPad or Mac. Belgian cybersecurity company ironPeak said it was a zero-click vulnerability: it could be triggered through a specially crafted iMessage without any action by the user.
According to ironPeak, the flaw could bypass BlastDoor, Apple’s protection mechanism designed to prevent malicious code from escaping the isolated iMessage environment. Apple fixed the issue in September with the release of iOS 27, iPadOS 27 and macOS 27 and credited Niels Hofmans of ironPeak for discovering it. Meta researchers confirmed ironPeak’s findings.