Dev News Daily ENDE

Apple patches an exploited flaw in iOS 26 and macOS 26 and 15, not in 27

Apple released updates for all of its operating systems on 28 September, but only the older branches carry a security fix, according to the SANS Internet Storm Center. The vulnerability, CVE-2026-86950, is patched in iOS 26, macOS 26 and macOS 15, and is already being exploited. iOS and macOS 27, released two weeks earlier, are not affected; the update for the current branch fixes functional issues only.

Apple credits Meta Product Security with reporting the flaw. According to SANS, Apple states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. SANS notes that a 27.1 release was also expected, to support a new foldable iPhone.

Apple patches an exploited flaw in iOS 26 and macOS 26 and 15, not in 27
Apple patches an exploited flaw in iOS 26 and macOS 26 and 15, not in 27 — Dev News Daily

What it means

The wording Apple uses, an extremely sophisticated attack against specific targeted individuals, usually describes spyware-grade exploitation rather than mass attacks, but the fix is the same for everyone: devices that cannot or have not moved to version 27 should take the update on the older branch now. For fleets that deliberately hold macOS or iOS one or two versions back, this is the case the older-branch patches exist for, and it is worth checking that they are actually being applied.

Primary source
SANS Internet Storm Center
https://isc.sans.edu/diary/rss/33376
Written by Victoria Shinder.