Apple has rolled out an emergency software patch for iOS 26, iPadOS 26 and macOS Ventura after confirming the flaw was being weaponised against a handful of individuals.
According to the company, the vulnerability allowed unauthorised code to execute on devices that had not yet installed the latest security build, exposing personal data and potentially enabling remote surveillance.
Security researchers first flagged the issue earlier this week, noting that the exploit appeared to target specific high‑profile users rather than being a broad‑scale worm.
What the vulnerability does
The bug resides in a core library that handles inter‑process communication, meaning a malicious app could bypass sandbox protections and gain access to the device’s microphone, camera and encrypted files.
Apple’s statement said the attack “was used to compromise specific targeted individuals” and that the flaw had been actively exploited in the wild for several weeks.
While the exact number of affected devices remains undisclosed, analysts estimate that a substantial proportion of the roughly 45 million iPhones, iPads and Macs still running iOS 26 are at risk.
How users can patch their devices
Apple advises anyone on iOS 26 or iPadOS 26 to open Settings → General → Software Update and install the “iOS 26.5.1” or “iPadOS 26.5.1” update, which is less than 200 megabytes and should complete within ten minutes on a typical Wi‑Fi connection.
Mac users are instructed to click the Apple menu, select System Settings, then Software Update and apply the “macOS Ventura 13.6.2” patch. The update is also available through the company’s Mobile Device Management (MDM) portals for corporate fleets.
Apple notes that the update does not remove any data and will retain existing settings, but it does require a device restart. Users should back up their data beforehand if they are uncomfortable with the process.
Broader implications for the Apple ecosystem
The episode underlines the challenge Apple faces in keeping older operating systems secure. iOS 26 was launched in late 2024 and, despite regular minor updates, many devices have lingered on the version because of carrier‑locked updates or user inertia.
Industry observers point out that the incident may accelerate Apple’s push to retire legacy software, a move it has hinted at in its 2025 sustainability roadmap.
For enterprises, the breach highlights the importance of timely patch management. Several security firms have already issued advisories urging IT departments to enforce the update across all managed Apple devices.
Regulators in the EU and the United States are watching the development closely. The European Commission’s cybersecurity arm has said it will assess whether the flaw constitutes a breach of the EU’s NIS 2 directive, which obliges companies to report significant incidents within 24 hours.
Meanwhile, privacy advocates warn that the episode could fuel calls for greater transparency around Apple’s bug‑bounty programme, which currently rewards researchers who disclose vulnerabilities directly to the company.
Apple’s emergency patch is now available in the App Store and through over‑the‑air updates. Users who have already installed the fix will see a confirmation banner in Settings, while those who postpone may receive a reminder notification each time they unlock their device.
The next scheduled iOS release, version 27, is expected in early 2027 and will incorporate additional hardening measures, according to Apple’s roadmap released last month.
For now, the company’s clear message is simple: install the update today, or risk having your personal information exposed to an unknown adversary.
Discussion (0)
Sign in to join the discussion.