Apple Patches Exploited iOS 26 and macOS 26 Graphics Bug, Plus Zero-Click iMessage Flaw
Apple patched an exploited graphics bug in iOS 26, iPadOS 26 and macOS 26, plus a separate zero-click iMessage flaw.
Apple said the now-fixed bug could be used to launch an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, according to the report. Details of the vulnerability were not released. A device's graphics engine typically has broad access to the rest of the operating system, and a successful exploit could potentially allow a hacker to steal a broad range of personal data from an affected device.
Meta's product security team was credited with the discovery, TechCrunch reported. When reached by TechCrunch, spokespeople for Apple and Meta did not provide comment about how the bug was discovered, how many people had their devices hacked because of the vulnerability, if any, or who may be exploiting it, such as government spyware makers or cybercriminals.
The bug affects Apple's previous generation of operating systems, which remains in wide usage. Almost four-in-five Apple iPhone owners are still running iOS 26, according to the company's own statistics. Devices running the latest version, iOS 27, iPadOS 27 and macOS 27, released earlier this month, also received a software update on Tuesday, but are unaffected by the bug under attack.
The security patch comes soon after Apple fixed another critical bug, known as CVE-2026-86869, which could have allowed hackers to silently steal data from affected iPhones, iPads or Macs. Belgian cybersecurity research firm ironPeak published a detailed writeup last week explaining that the bug was a zero-click vulnerability that could be invisibly triggered via a maliciously crafted iMessage, without the user's knowledge.
Such bugs require no interaction from the victim, such as clicking a link, and are highly sought after by surveillance vendors and spyware makers. According to ironPeak's post, the bug could bypass BlastDoor, a security feature Apple implemented to prevent malicious code, like spyware, from escaping iMessage's sandbox and hacking the user's device.
Apple fixed the bug in September with the release of iOS 27, iPadOS 27 and macOS 27, and credited ironPeak's Niels Hofmans with the discovery, alongside security researchers at Meta who confirmed their findings in a post on X. It is not yet known if this bug had been used in cyberattacks before it was fixed.