Apple’s Last Actively Exploited Bug Disclosure Was iOS 26.2, Nine Months Ago

Apple logo
Credits: Apple

The most recent Apple security document to say a bug may have been exploited is iOS 26.2, published December 12, 2025. Both flagged issues sat in WebKit, and Apple credited Google’s Threat Analysis Group on each one.

Apple iPhone 18 Pro Photos app Apple Reference Image
Apple's iOS interface. Apple has not yet published a security content document for iOS 27. Image: Apple

Six Apple releases since then, running through September 8, 2026, carry no equivalent notice, based on Apple’s own published documents.

Key facts on the iOS 26.2 disclosure

ItemApple’s document
ReleaseiOS 26.2 and iPadOS 26.2
PublishedDecember 12, 2025
Support articlesupport.apple.com/en-us/125884
CVEs with an exploitation noticeCVE-2025-43529, CVE-2025-14174
ComponentWebKit, both entries
CreditGoogle Threat Analysis Group; Apple and Google Threat Analysis Group
A presenter on stage at an Apple event. Apple's security disclosures are handled on separate support pages, not at product events.

Apple’s exact wording, and what it does not say

Apple’s own sentence on both entries reads: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26.” That wording names no attacker, no spyware product and no device model. Apple limits the description to “specific targeted individuals” rather than a broad population of users, and its report language stops short of confirming the exploitation independently rather than citing an outside report.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

The two entries are not identical. Apple’s impact line for CVE-2025-43529 reads “processing maliciously crafted web content may lead to arbitrary code execution,” credited solely to Google’s Threat Analysis Group. CVE-2025-14174 carries a narrower impact line, “processing maliciously crafted web content may lead to memory corruption,” and a joint credit to Apple and Google’s Threat Analysis Group, meaning Apple’s own engineers share the find on that second entry. Both sit under the same WebKit heading and the same exploitation sentence, which Apple repeats verbatim rather than varying between the two.

iOS 27 iPadOS 27
iPadOS 27. The iOS 26.2 exploitation notice applied to iPadOS 26.2 as well. Image: Apple

Six releases since, with no matching notice

ReleaseDateExploitation notice in Apple’s document
iOS 26.2Dec 12, 2025Two CVEs, both WebKit
iOS 26.5May 11, 2026None
iOS 26.5.2Jun 29, 2026None
iOS 26.6Jul 27, 2026None
iOS 26.6.1Aug 17, 2026None
iOS 26.6.2Sep 8, 2026Zero CVEs published

Why this is worth tracking rather than assuming

Apple does not maintain a running tally of exploited-bug disclosures anywhere on its own pages; the only way to know the count is to read each document in turn. None of the six releases above changes the December 2025 finding or extends it to a later iOS version, and none of them names a new exploited issue of its own. That gap of nine months is the plain distance between the last such notice and today, not a claim that no device has ever been affected.

The gap holds even where a release fixed a serious-sounding issue without exploitation language attached. iOS 26.6.1, for one, patched a Telephony bug that Apple’s own impact line described as letting an attacker in a privileged network position bypass IPSec authentication and intercept network traffic, and that document still carries no “may have been exploited” sentence anywhere in it. A serious impact description and an exploitation notice are two separate things on Apple’s own documents, and only the second one is what this article is counting.

What this means going into iOS 27

Apple has not published a security content document for iOS 27 yet, so there is nothing to check there for an exploitation notice as of this weekend. Apple’s September 9 event, which introduced the iPhone 18 Pro and iPhone Duo, did not touch on security disclosures at all; that document, when it appears, will be the one to read.

What Apple has not said

Apple has not said how many exploited-in-the-wild reports it receives that never surface in a public document, has not named the party behind the iOS 26.2 attack beyond crediting the researchers who reported it, and has not stated whether the nine-month gap reflects fewer attacks, slower detection, or neither.

As of Sunday, September 13, 2026, iOS 26.2 remains the last Apple release to carry an exploitation notice. Anyone tracking the count can check support.apple.com/en-us/100100 directly once Apple documents whatever ships with iOS 27 on Monday.