Apple Patches CVE-2026-86950 in iOS 26 as 4-in-5 iPhones Still Run Older Software
Updated
Updated · TechCrunch · Sep 29
Apple Patches CVE-2026-86950 in iOS 26 as 4-in-5 iPhones Still Run Older Software
3 articles · Updated · TechCrunch · Sep 29
Summary
Apple said CVE-2026-86950 may have been used in extremely sophisticated attacks against specific targets on pre-iOS 27 devices, prompting fixes across iOS 26, iPadOS 26 and macOS 26.
The flaw sat in CoreGraphics, the graphics engine with broad system access; Apple withheld technical details, but a successful exploit could expose a wide range of personal data.
Meta’s product security team found the bug, while Apple and Meta gave no details on how it was discovered, who exploited it, or whether any users were confirmed hacked.
Nearly 4 in 5 iPhones still run iOS 26, keeping the older software widely exposed even after Apple also shipped Tuesday updates for iOS 27, iPadOS 27 and macOS 27, which were not vulnerable.
The patch follows Apple’s recent fix for CVE-2026-86869, a zero-click iMessage flaw that researchers said could bypass BlastDoor and silently compromise devices.