Apple patches iOS 26, iPadOS 26 and macOS 26 after targeted attack warning
The fix matters most for people still on the older releases, because Apple says the flaw may already have been used against specific targets.
Apple has shipped a security update for iOS 26, iPadOS 26, and macOS 26 after saying a flaw in the graphics engine may already have been used in highly targeted attacks, which makes this relevant for anyone still on those older releases. The issue is tracked as CVE-2026-86950, and Apple says Meta’s product security team found it. Apple’s own figures say nearly four in five iPhone users are still on iOS 26, so the exposure is still broad even though the latest iOS 27, iPadOS 27, and macOS 27 builds were also patched on Tuesday. The company also recently fixed a separate zero-click bug, CVE-2026-86869, that could have let attackers extract data through a malicious iMessage and bypass BlastDoor.
Why it matters
With almost four-in-five iPhone owners still on iOS 26, the patch closes a risk that affects a large installed base, not just a small group of holdouts. It also shows Apple is dealing with more than one serious iMessage and graphics-engine issue at once, which raises the urgency for users to update across iPhone, iPad and Mac.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- TechCrunch