Apple has patched a security flaw affecting iOS 26, iPadOS 26 and macOS 26 that the company says may have already been used by attackers. The company said the bug could enable a highly targeted attack aimed at specific individuals running versions of iOS released before iOS 27. Apple disclosed the fix through its security pages, where the issue is tracked as CVE-2026-86950.
The vulnerability sat in the primary graphics engine responsible for the interface and visuals on iPhones, iPads and Macs. Apple did not publish specifics about the defect, but that component generally holds wide access across a device's operating system. An attacker who successfully exploited it could potentially obtain a broad range of personal information from an affected device.
Apple and Meta spokespeople declined to answer questions about how the flaw was found or how many devices, if any, were compromised. It also remains unknown who might be using the bug, whether government spyware operations or criminal groups. The affected software is the prior generation of Apple's operating systems, which is still heavily deployed; company statistics cited by TechCrunch indicate nearly four in five iPhone owners remain on iOS 26. Devices on iOS 27, iPadOS 27 and macOS 27, released earlier in the month, also got a software update on Tuesday but are not exposed to the bug under attack.
The disclosure follows Apple's repair of a separate critical vulnerability, CVE-2026-86869, which could have let attackers quietly extract data from iPhones, iPads and Macs. Belgian cybersecurity firm ironPeak published a detailed analysis last week describing that earlier bug as a zero-click exploit that a maliciously crafted iMessage could trigger invisibly, without the user's knowledge. Zero-click flaws require no victim action and are prized by surveillance vendors and spyware developers.
According to ironPeak's write-up, that exploit could get around BlastDoor, an Apple security feature designed to stop malicious code such as spyware from leaving iMessage's sandbox and compromising a device. Apple resolved the issue in September with the release of iOS 27, iPadOS 27 and macOS 27, crediting ironPeak researcher Niels Hofmans with the find, along with Meta security researchers who corroborated the results in a post on X. It is not known whether that bug was used in attacks before the fix shipped.
More software news from TechManNews.







