Apple has fixed a security vulnerability affecting iPhones, iPads and Macs running its previous-generation operating systems, warning that the flaw may have been exploited in a sophisticated attack targeting specific individuals.
The vulnerability, identified as CVE-2026-86950, affects iOS 26, iPadOS 26 and macOS 26. Apple said the flaw could have been used as part of an “extremely sophisticated attack” against targeted individuals using versions of its operating systems released before iOS 27.
The company has released security updates for affected devices and is urging users who have not yet upgraded to install the latest available software.
Vulnerability found in graphics engine
According to Apple’s security advisory, the flaw was found in the graphics component responsible for rendering the user interface and visual content on Apple devices.
Meta’s product security team was credited with discovering the vulnerability.
Apple has not publicly disclosed technical details about how the flaw could be exploited or how many users, if any, were affected by attacks using it.
It also remains unclear who may have been behind any exploitation, including whether the vulnerability was used by commercial spyware operators, government-linked groups or cybercriminals.
Because graphics components can interact with other parts of an operating system, successfully exploiting such a flaw could potentially provide attackers with access to sensitive information. However, the extent of access possible through this specific vulnerability has not been publicly confirmed.
Millions of devices could still be affected
Although iOS 26 and other affected operating systems have been superseded by newer versions, they remain widely used.
Apple’s developer statistics indicate that a large majority of iPhone users are still running iOS 26, meaning many devices could remain exposed until their software is updated.
Apple’s latest-generation operating systems, including iOS 27, iPadOS 27 and macOS 27, also received security updates but are not affected by CVE-2026-86950.
Another critical Apple flaw recently fixed
The latest warning comes shortly after Apple addressed another serious vulnerability, CVE-2026-86869, which researchers described as a zero-click security flaw.
Belgian cybersecurity firm ironPeak said the vulnerability could be triggered through a specially crafted iMessage without requiring the victim to click a link or interact with the message.
The firm said the flaw could bypass Apple’s BlastDoor security mechanism, which is designed to isolate potentially malicious content delivered through iMessage.
Apple fixed the vulnerability with updates to iOS 27, iPadOS 27 and macOS 27. The company credited ironPeak researcher Niels Hofmans and Meta security researchers for identifying the issue.
It remains unclear whether the zero-click vulnerability was exploited in real-world attacks before Apple released the fix.
What users should do
Users running iOS 26, iPadOS 26 or macOS 26 should check for available software updates and install the latest security release.


