Updated
Updated · TechCrunch · Sep 29
Apple Patches CVE-2026-86950 in iOS 26 as 4-in-5 iPhones Still Run Older Software
Updated
Updated · TechCrunch · Sep 29

Apple Patches CVE-2026-86950 in iOS 26 as 4-in-5 iPhones Still Run Older Software

3 articles · Updated · TechCrunch · Sep 29

Summary

  • Apple said CVE-2026-86950 may have been used in extremely sophisticated attacks against specific targets on pre-iOS 27 devices, prompting fixes across iOS 26, iPadOS 26 and macOS 26.
  • The flaw sat in CoreGraphics, the graphics engine with broad system access; Apple withheld technical details, but a successful exploit could expose a wide range of personal data.
  • Meta’s product security team found the bug, while Apple and Meta gave no details on how it was discovered, who exploited it, or whether any users were confirmed hacked.
  • Nearly 4 in 5 iPhones still run iOS 26, keeping the older software widely exposed even after Apple also shipped Tuesday updates for iOS 27, iPadOS 27 and macOS 27, which were not vulnerable.
  • The patch follows Apple’s recent fix for CVE-2026-86869, a zero-click iMessage flaw that researchers said could bypass BlastDoor and silently compromise devices.

Insights

Why are older Apple devices still prime targets for image- and PDF-based exploits even after emergency patches arrive?
Could a single booby-trapped image or PDF hijack your older iPhone or Mac, and why is Apple rushing out emergency fixes now?