PhonesComputers

Apple Patches Exploited Graphics Bug in iOS 26, iPadOS 26, macOS 26

Apple released a security fix for CVE-2026-86950, a graphics engine flaw in iOS 26, iPadOS 26 and macOS 26 that may have been exploited in targeted attacks.

Apple has released a security fix for a vulnerability in iOS 26, iPadOS 26 and macOS 26 that the company says may have been exploited. The bug, officially classed as CVE-2026-86950, was found in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs.

According to Apple, the flaw could be used to launch an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Meta's product security team was credited with the discovery.

Apple also released a software update on Tuesday for devices running iOS 27, iPadOS 27 and macOS 27, which are unaffected by the bug. Earlier this month, Apple released those newer operating systems.

The patch follows a separate fix in September, when Apple addressed the zero-click bug CVE-2026-86869 with the release of iOS 27, iPadOS 27 and macOS 27, crediting ironPeak's Niels Hofmans and security researchers at Meta. Last week, Belgian cybersecurity research firm ironPeak published a writeup explaining that CVE-2026-86869 was a zero-click vulnerability triggerable via a maliciously crafted iMessage and capable of bypassing BlastDoor.

According to Apple's own statistics, almost four-in-five of Apple's iPhone owners are still running iOS 26, making the latest patch widely relevant. The update is available now for affected devices.

Quick answers

What is CVE-2026-86950?

It is a vulnerability in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs, affecting iOS 26, iPadOS 26 and macOS 26.

Which devices are affected by the bug?

Devices running iOS 26, iPadOS 26 and macOS 26 are affected. Devices running iOS 27, iPadOS 27 and macOS 27 are unaffected.

Who discovered the vulnerability?

Meta's product security team was credited with the discovery of CVE-2026-86950.

Source