The security vulnerability, tracked as CVE-2026-86950, resides within the core graphics engine responsible for system visuals. By compromising this component, attackers can gain broad access to the operating system and potentially exfiltrate sensitive personal data. Meta’s product security team discovered the flaw, though both Apple and Meta have declined to comment on the scope of the attacks or the identity of the threat actors involved.
While devices running the latest iOS 27, iPadOS 27, and macOS 27 received a precautionary update on Tuesday, these newer versions are not susceptible to the specific exploit targeting the previous generation. This patch follows another recent fix for a zero-click vulnerability, CVE-2026-86869, which allowed attackers to bypass Apple’s BlastDoor security feature via iMessage. That exploit, identified by Belgian firm ironPeak, enabled silent data theft without requiring any user interaction. Users are strongly advised to update their devices immediately to mitigate these active risks.

Comments (0)
No comments yet. Be the first!