Apple has fixed a security vulnerability in its iOS 26, iPadOS 26 and macOS 26 operating systems that the company says “may have been exploited” by hackers. The tech giant said the now-fixed bug could be used to launch “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
According to a listing on Apple’s security pages, the bug was found in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs.
Meta’s product security team was credited with the discovery.
Details of the bug, officially classed as CVE-2026-86950, were not released, but a device’s graphics engine typically has broad access to the rest of the device’s operating system. A successful exploit could potentially allow a hacker to steal a broad range of personal data from an affected device.
When reached by TechCrunch, spokespeople for Apple and Meta did not provide comment about how the bug was discovered, or how many people had their devices hacked due to this vulnerability, if any. It’s also unclear who may be exploiting the bug, such as government spyware makers or cybercriminals.
While the bug affects Apple’s previous generation of operating systems, it remains in wide usage. Almost four-in-five of Apple’s iPhone owners are still running iOS 26, according to the company’s own statistics. Devices running the latest version, iOS 27, iPadOS 27, and macOS 27, released earlier this month, also received a software update on Tuesday, but are unaffected by the bug under attack.
A separate ‘zero-click’ bug now fixed
News of the security patch comes soon after Apple fixed another critical security bug, known as CVE-2026-86869, which could have allowed hackers to silently steal data from affected iPhones, iPads, or Macs.
Belgian cybersecurity research firm ironPeak published a detailed writeup last week explaining that the bug was a “zero-click” vulnerability that could be invisibly triggered via a maliciously crafted iMessage, without the user’s knowledge. Such bugs require no interaction from the victim, such as clicking a link, and are highly sought-after by surveillance vendors and spyware makers.
Per ironPeak’s post, the bug is capable of bypassing BlastDoor, a security feature that Apple implemented to prevent malicious code, like spyware, from escaping iMessage’s sandbox and hacking the user’s device.
Apple fixed the bug in September with the release of iOS 27, iPadOS 27, and macOS 27, and credited ironPeak’s Niels Hofmans with the discovery, alongside security researchers at Meta who confirmed their findings in a post on X.
It’s not yet known if this bug had been used in cyberattacks before it was fixed.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



