Apple Fixes iOS 26 Security Vulnerability Used in Targeted Attacks
Apple fixed an iOS 26 security flaw that may have been exploited in targeted attacks against specific users across older operating systems.
Apple has fixed a security vulnerability affecting iOS 26, iPadOS 26, and macOS 26 after warning that the flaw may have been used in a highly targeted attack against specific users.
The vulnerability, tracked as CVE-2026-86950, was found in Apple’s graphics engine that powers interface visuals across iPhone, iPad, and Mac devices. Apple’s security update addressed the issue and noted that the company was aware it may have been actively exploited.
Security Fix Targets Older Apple Operating Systems
Apple said the vulnerability affected previous-generation operating systems that remain widely used. The company’s latest iOS 27, iPadOS 27, and macOS 27 releases were not affected by this specific issue.
Meta’s product security team was credited with discovering the flaw. Apple did not publicly release details about the vulnerability, but security issues involving core graphics components can potentially provide access to sensitive areas of a device if successfully exploited.
Apple’s platform security updates come as the company continues to address vulnerabilities across its operating systems and developer ecosystem.
Apple Also Fixed Separate Zero-Click iMessage Bug
The update follows another security issue involving Apple devices, tracked as CVE-2026-86869. The flaw was described as a zero-click vulnerability that could let attackers trigger malicious activity through a specially crafted iMessage without user interaction.
Security researchers at ironPeak detailed the iMessage vulnerability, including how it could bypass Apple’s BlastDoor protection, which is designed to limit malicious code inside iMessage.
Apple fixed the issue through updates to iOS 27, iPadOS 27, and macOS 27. Apple credited security researchers involved in identifying the vulnerability, including researchers from Meta.
Meta security researchers also shared information about their findings related to the vulnerability.
Apple has not confirmed whether the zero-click vulnerability was used in real-world attacks before it was patched.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0