Apple released a broad set of iOS updates spanning current and legacy devices, urging users to install them to avoid serious reliability issues. Reported releases include iOS 26.2.1 for newer devices and parallel updates for older models (e.g., iOS 18.7.4, iOS 16.7.13, iOS 15.8.6, and iOS 12.5.8), covering hardware as old as the iPhone 5s/6 era and affecting an estimated 2+ billion iPhones globally.
For the oldest supported devices, Apple’s notes indicate the updates are not feature or security patches but a certificate update intended to keep core Apple services functioning beyond January 2027, including iMessage, FaceTime, device activation, and Apple account sign-in. Separately, Apple also tied the urgency of updating to reports of emergency-calling failures on some older iPhones under rare network conditions (notably highlighted after incidents in Australia), positioning the releases as necessary to maintain both service continuity and critical calling functionality.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Apple also pushed a wider set of urgent software updates across current and older iPhone models and released watchOS 26.2.1 for cellular Apple Watch Series 6 and later. Apple urged users to install the updates promptly, with reporting linking part of the urgency to emergency-calling reliability issues, especially noted in Australia.
On or before January 27, 2026, Apple released iOS 12.5.8, iOS 15.8.6, and iOS 16.7.13 for older iPhone and iPad models. The updates were intended to refresh security certificates so iMessage, FaceTime, Apple account sign-in, and device activation would continue working beyond January 2027, rather than to fix vulnerabilities or add features.
Before the January 2026 releases, Apple had last issued patches for the iOS 15 and iOS 16 branches in mid-2025. These older supported branches then remained unchanged until the later maintenance update.
Apple's iOS 12 branch previously received an update in January 2023, after which it went unpatched for roughly three years. This established the long gap before Apple revisited the legacy platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcetechrepublic.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.