Apple has fixed a security vulnerability found in iOS 26, iPadOS 26 and macOS 26. The company said the flaw may already have been exploited by hackers and could have been used in extremely sophisticated attacks targeting users on versions before iOS 27.
On Sept. 29, U.S. tech media outlet TechCrunch reported the vulnerability was found in a core graphics engine that handles the user interface and screen processing on iPhones, iPads and Macs.
Apple classified the vulnerability as CVE-2026-86950. It did not disclose detailed technical information, but said the graphics engine is a component with broad access across the operating system, meaning a successful attack could leak a range of personal information stored on a device.
Meta’s security team found the vulnerability. Apple and Meta did not provide further explanation of how it was identified, whether there were any real victims and, if so, how many. It has not been confirmed who exploited the flaw. It has not been disclosed whether it was a spyware maker for governments or an ordinary cybercrime group.
The impact is not small. The flaw occurred in an older generation of operating systems, but many users still use them. Apple statistics show about 4 out of 5 iPhone users are still on iOS 26. The latest versions released earlier this month, iOS 27, iPadOS 27 and macOS 27, were not affected by the vulnerability targeted in the attack. Apple nonetheless provided a separate software update for the latest versions on the same day.
The patch follows Apple’s recent fix for another major vulnerability, CVE-2026-86869. The flaw was cited as a problem that could lead to data theft on iPhones, iPads and Macs without users knowing.
Belgian cybersecurity research firm IronPeak published an analysis last week on the earlier vulnerability. IronPeak said the flaw was a “zero-click” vulnerability that could be executed through a malicious iMessage without any user action. It also said the structure allows attacks even if a user does not click a link, making it a type preferred by surveillance software firms or spyware makers.
IronPeak said the vulnerability could also bypass Apple’s security feature BlastDoor. BlastDoor was introduced to prevent malicious code inside iMessage from escaping the sandbox and compromising an entire device. Apple fixed the flaw during the September release of iOS 27, iPadOS 27 and macOS 27, and credited IronPeak’s Niels Hofmans (닐스 호프만스) and Meta researchers for the discovery. The Meta researchers later confirmed related details on X.
It has not yet been confirmed whether the vulnerability was used in real cyberattacks before it was fixed. As a result, users who continue to use iOS 26, iPadOS 26 and macOS 26 need to first check whether they have applied the latest security updates.