{
  "id": 10701344,
  "title": "Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix",
  "url": "https://urgent.news/2026/09/29/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T13:25:21.000Z",
  "source": {
    "name": "TechCrunch",
    "slug": "techcrunch",
    "url": "https://techcrunch.com/2026/09/29/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix/"
  },
  "original_language": "en",
  "account": "Apple has patched a security flaw in iOS 26, iPadOS 26, and macOS 26 operating systems, which hackers may have taken advantage of. The vulnerability, officially labeled CVE-2026-86950, existed within the primary graphics engine responsible for the user interface and visuals on iPhones, iPads, and Macs, according to Apple's security pages. The bug was discovered by Meta's product security team. Although the specifics of the flaw were not disclosed, a device's graphics engine typically possesses extensive access to the rest of its operating system. A successful exploitation could potentially permit a hacker to extract extensive personal data from the affected device. Apple and Meta declined to disclose how the bug was discovered or how many users fell victim to this vulnerability, if any. The bug affects older versions of Apple's operating systems, which are still widely used, with nearly four out of five iPhone owners still on iOS 26. However, devices running the latest versions, iOS 27, iPadOS 27, and macOS 27, released earlier this month, are not susceptible to this bug. This security update follows another critical security patch from Apple, CVE-2026-86869, which could have allowed hackers to surreptitiously extract data from iPhones, iPads, or Macs via a maliciously crafted iMessage, without the user's knowledge.",
  "summary": "Apple says the bug was used to attack \"specific targeted individuals\" running iOS 26, which the majority of Apple customers are still using.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}