<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz" -->

---
title: Still running iOS 26? Update your iPhones, iPads and...
description: Apple has patched a security vulnerability (CVE-2026-86950) in iOS 26, iPadOS 26, and macOS 26 that may have been exploited in sophisticated attacks against...
canonical: https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | daily.dev
og:description: Apple has patched a security vulnerability (CVE-2026-86950) in iOS 26, iPadOS 26, and macOS 26 that may have been exploited in sophisticated attacks against...
og:url: https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz
og:image: https://api.daily.dev/og/posts/wpYwMxZvz.png
og:image:alt: Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix

**[TechCrunch](https://daily.dev/sources/tc)** · 3 min read · 0 upvotes · 0 comments

## Summary

Apple has patched a security vulnerability (CVE-2026-86950) in iOS 26, iPadOS 26, and macOS 26 that may have been exploited in sophisticated attacks against specific targeted individuals. The flaw was found in the main graphics engine, which has broad system access, and was discovered by Meta's product security team. Around four-in-five iPhone users are still on iOS 26 and need to update, even though iOS 27 devices are unaffected. Separately, a zero-click iMessage vulnerability (CVE-2026-86869) that bypassed Apple's BlastDoor protection was also recently fixed in iOS 27, discovered by Belgian firm ironPeak and confirmed by Meta researchers.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://techcrunch.com/2026/09/29/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix>

## Questions this post answers

### What is CVE-2026-86950 and does it affect iOS 26?

CVE-2026-86950 is a vulnerability in the main graphics engine powering the user interface on iPhones, iPads, and Macs running iOS 26, iPadOS 26, and macOS 26. Apple says it may have been exploited in an extremely sophisticated attack against specific targeted individuals, and it credited Meta's product security team with the discovery. Devices on iOS 27 are unaffected but still received an update.

_Track critical CVE disclosures like this one on daily.dev before an unpatched device becomes a liability._

### What was the zero-click iMessage vulnerability that bypassed BlastDoor on iPhones?

CVE-2026-86869 was a zero-click vulnerability that could be silently triggered through a maliciously crafted iMessage without any user interaction, bypassing Apple's BlastDoor sandboxing protection. Belgian security firm ironPeak, specifically researcher Niels Hofmans, discovered and published details on the bug, with Meta researchers confirming the findings. Apple fixed it in September with the release of iOS 27, iPadOS 27, and macOS 27.

_Developers securing messaging-adjacent apps can follow zero-click exploit writeups like this on daily.dev._

## Similar posts on daily.dev

- [Apple patches CoreGraphics zero-day flaw exploited in attacks](https://daily.dev/posts/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks-0ov4mhz7v) · BleepingComputer · 0 upvotes · 0 comments
- [Apple Speeds iPhone Security Patches to Counter AI-Driven Hacking Threats](https://daily.dev/posts/apple-speeds-iphone-security-patches-to-counter-ai-driven-hacking-threats-swfx2p7ck) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#apple](https://daily.dev/tags/apple), [#ios](https://daily.dev/tags/ios), [#mac](https://daily.dev/tags/mac)

[View this post on daily.dev](https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix","url":"https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz"},"datePublished":"2026-09-29T13:30:03.020Z","dateModified":"2026-09-29T13:30:31.850Z","description":"Apple has patched a security vulnerability (CVE-2026-86950) in iOS 26, iPadOS 26, and macOS 26 that may have been exploited in sophisticated attacks against...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c838a3a0829bbd0d3607c52ea56f974b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c838a3a0829bbd0d3607c52ea56f974b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"TechCrunch","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"TechCrunch","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tc","url":"https://daily.dev/sources/tc"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,apple,ios,mac","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"TechCrunch","item":"https://daily.dev/sources/tc"},{"@type":"ListItem","position":3,"name":"Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix-wpywmxzvz#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-86950 and does it affect iOS 26?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-86950 is a vulnerability in the main graphics engine powering the user interface on iPhones, iPads, and Macs running iOS 26, iPadOS 26, and macOS 26. Apple says it may have been exploited in an extremely sophisticated attack against specific targeted individuals, and it credited Meta's product security team with the discovery. Devices on iOS 27 are unaffected but still received an update. Track critical CVE disclosures like this one on daily.dev before an unpatched device becomes a liability."}},{"@type":"Question","name":"What was the zero-click iMessage vulnerability that bypassed BlastDoor on iPhones?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-86869 was a zero-click vulnerability that could be silently triggered through a maliciously crafted iMessage without any user interaction, bypassing Apple's BlastDoor sandboxing protection. Belgian security firm ironPeak, specifically researcher Niels Hofmans, discovered and published details on the bug, with Meta researchers confirming the findings. Apple fixed it in September with the release of iOS 27, iPadOS 27, and macOS 27. Developers securing messaging-adjacent apps can follow zero-click exploit writeups like this on daily.dev."}}]}
```

