Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Apple Patches iOS 26 Flaw Already Exploited Against Targeted Individuals, Four in Five iPhones Still Exposed

Apple pushed out a batch of software updates Monday, September 28, and buried in the pile is a patch for a bug the company says has already been weaponized against real people.
iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 all close the same hole: CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics, the framework that handles image and PDF rendering across every Apple device, according to Apple's own security advisory as reported by MacRumors and 9to5Mac. Apple's language is blunt. The company says it's aware of a report that the flaw "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
Translation: this wasn't some theoretical lab exploit. Somebody used it.
Meta's Product Security team gets the credit for reporting the bug, according to Apple's advisory cited by TechCrunch and 9to5Mac. Apple hasn't said how many people were targeted, whether any of the attacks actually succeeded, or when the exploitation started. TechCrunch reached out to both Apple and Meta for more detail and got nothing back.
Four in five iPhones are exposed
Roughly four-in-five iPhone owners are still running iOS 26 rather than the newer iOS 27, which launched two weeks earlier in September and is not affected by this bug, according to Apple's own usage statistics cited by TechCrunch. That's a massive pool of unpatched devices sitting on a known, already-exploited vulnerability the moment Apple's advisory went public.
Johannes Ullrich of the SANS Internet Storm Center noted that iOS 27.0.1, released the same day with no published CVE entries, backs up Apple's claim that the current operating system wasn't affected, according to NotebookCheck. That's a fair technical read of the situation, but it doesn't change the math for the majority of users who haven't upgraded.
If you're on an older device that can't run iOS 27 at all, you're still covered. NotebookCheck reports that iPad models Apple has cut off from iPadOS 27, including the third-generation iPad Pro 12.9-inch, the first-generation iPad Pro 11-inch, the third-generation iPad Air, the eighth-generation iPad, and the fifth-generation iPad mini, all received iPadOS 26.7.1 instead. Devices that no longer get any updates at all got nothing Monday, and Apple hasn't said whether those older, unsupported versions carry the same flaw.
A second, separate bug adds to the picture
This isn't the only serious vulnerability Apple has dealt with this month. TechCrunch reported that Belgian cybersecurity firm ironPeak, specifically researcher Niels Hofmans, published a detailed writeup on a separate zero-click iMessage bug, CVE-2026-86869, that could bypass BlastDoor, the sandbox Apple built to stop malicious code from escaping a text message and taking over the device. Meta researchers confirmed ironPeak's findings on X, according to TechCrunch. Apple fixed that one earlier in September with the iOS 27 release itself. It's still not known whether that bug was actually used against anyone before it got patched.
Zero-click exploits that require no user interaction, no tapped link, nothing, are highly sought after in the vulnerability market. They're the tools surveillance vendors and spyware makers pay the most for, because the target never sees it coming.
Who's behind the CoreGraphics attack? Nobody's saying
The obvious question is who was doing the targeting. Apple's phrasing, "extremely sophisticated attack against specific targeted individuals," is the same kind of language the company has used in the past to describe attacks linked to government-grade spyware operators. That's a reasonable inference based on the pattern, not a confirmed fact. Neither Apple nor Meta has named a suspect, a spyware vendor, or a government, and no source in this reporting makes that claim on the record. Treat it as an open question, not a conclusion.
Apple also used Monday's release to clean up unrelated bugs in the brand-new iOS 27. iOS 27.0.1 fixes unexpected restarts tied to Face ID failures on the iPhone 18 Pro and Pro Max, according to NotebookCheck and 9to5Mac, along with color artifacts in 2x zoom photos and a touchscreen freeze that hit when Notification Center and Control Center were opened at the same time. watchOS 27.0.1 and visionOS 27.0.1 shipped the same day with no security entries attached.
None of that matters if your iPhone is still sitting on iOS 26. The patch is under Settings, General, Software Update, listed separately from the iOS 27 upgrade. Apple hasn't disclosed a victim count, a timeline, or an attacker, and there's no indication any of that information is coming. The update is the only concrete action available to users right now.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.