苹果已经修复了 iOS 26、iPadOS 26 和 macOS 26 操作系统中的一处安全漏洞。公司称,黑客“可能已经利用了”该漏洞。这家科技巨头表示,这个现已修复的漏洞可能被用于对运行 iOS 27 之前各版本 iOS 的“特定目标个人发起极其复杂的攻击”。据苹果安全页面上的信息,该漏洞存在于为 iPhone、iPad 和 Mac 用户界面及视觉效果提供支持的主要图形引擎中。这一漏洞由 Meta 产品安全团队发现。
Apple has fixed a security vulnerability in its iOS 26, iPadOS 26 and macOS 26 operating systems that the company says “may have been exploited” by hackers. The tech giant said the now-fixed bug could be used to launch “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”According to a listing on Apple’s security pages, the bug was found in the main graphics engine that powers the user interface and visuals on iPhones, iPads and Macs. Meta’s product security team was credited with the discovery.
该漏洞的官方编号为 CVE-2026-86950,但苹果尚未公布漏洞详情。设备图形引擎通常能够广泛访问设备操作系统的其他部分,因此成功利用该漏洞或许可以让黑客从受影响的设备中窃取大量个人数据。
Details of the bug, officially classed as CVE-2026-86950, were not released, but a device’s graphics engine typically has broad access to the rest of the device’s operating system. A successful exploit could potentially allow a hacker to steal a broad range of personal data from an affected device.
TechCrunch 联系苹果和 Meta 时,两家公司均未就漏洞是如何被发现的,以及有多少人的设备因该漏洞遭到黑客入侵(如果有的话)置评。目前也不清楚是谁可能正在利用该漏洞,例如政府间谍软件制造商或网络犯罪分子。
When reached by TechCrunch, spokespeople for Apple and Meta did not provide comment about how the bug was discovered, or how many people had their devices hacked due to this vulnerability, if any. It’s also unclear who may be exploiting the bug, such as government spyware makers or cybercriminals.
尽管该漏洞影响苹果上一代操作系统,但这些系统仍被广泛使用。据苹果自身统计,接近五分之四的 iPhone 用户仍在运行 iOS 26。运行本月早些时候发布的最新版本 iOS 27、iPadOS 27 和 macOS 27 的设备也于周二获得了软件更新,但不受该漏洞影响。
While the bug affects Apple’s previous generation of operating systems, it remains in wide usage. Almost four-in-five of Apple’s iPhone owners are still running iOS 26, according to the company’s own statistics. Devices running the latest version, iOS 27, iPadOS 27, and macOS 27, released earlier this month, also received a software update on Tuesday, but are unaffected by the bug under attack.
就在此次安全补丁发布前不久,苹果刚刚修复了另一个关键安全漏洞,编号为 CVE-2026-86869。该漏洞可能允许黑客在受影响的 iPhone、iPad 或 Mac 上悄无声息地窃取数据。
News of the security patch comes soon after Apple fixed another critical security bug, known as CVE-2026-86869, which could have allowed hackers to silently steal data from affected iPhones, iPads, or Macs.
比利时网络安全研究公司ironPeak上周发布了一份详细报告,解释称,该漏洞是一种“零点击”漏洞,可通过恶意构造的iMessage在用户不知情的情况下被悄然触发。此类漏洞无需受害者进行任何交互,例如点击链接,因此备受监控软件供应商和间谍软件制造商的青睐。
Belgian cybersecurity research firm ironPeak published a detailed writeup last week explaining that the bug was a “zero-click” vulnerability that could be invisibly triggered via a maliciously crafted iMessage, without the user’s knowledge. Such bugs require no interaction from the victim, such as clicking a link, and are highly sought-after by surveillance vendors and spyware makers.
据ironPeak的帖子称,该漏洞能够绕过BlastDoor。这是苹果为阻止间谍软件等恶意代码逃离iMessage沙箱并入侵用户设备而实施的一项安全功能。
Per ironPeak’s post, the bug is capable of bypassing BlastDoor, a security feature that Apple implemented to prevent malicious code, like spyware, from escaping iMessage’s sandbox and hacking the user’s device.
苹果在9月发布iOS 27、iPadOS 27和macOS 27时修复了该漏洞,并将漏洞的发现归功于ironPeak的Niels Hofmans以及Meta的安全研究人员。后者在一篇发表于……的帖文中证实了他们的发现。目前尚不清楚,该漏洞在修复前是否曾被用于网络攻击。
Apple fixed the bug in September with the release of iOS 27, iPadOS 27, and macOS 27, and credited ironPeak’s Niels Hofmans with the discovery, alongside security researchers at Meta who confirmed their findings in a post on It’s not yet known if this bug had been used in cyberattacks before it was fixed.