Apple is reportedly preparing a fix for an iOS 26 bug that can permanently lock users out of their iPhones when a custom alphanumeric passcode includes a special character removed from the lock-screen keyboard. The issue drew attention after university student Connor Byrne said his iPhone 13 became inaccessible because his passcode used the Czech caron/háček character, which disappeared from the available keyboard options after the September 2025 update.
Because the missing character could no longer be entered, affected users were left with a choice between staying locked out or performing a factory reset that would erase locally stored data such as photos and files. Reports say Apple engineers began investigating after Byrne's account spread online and are now working on a targeted remedy for a future major iOS 26 release, though the company has not publicly confirmed a timeline or responded to media requests for comment.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
According to reporting, Apple engineers became aware of the issue last week and started internal work on a software fix shortly after Byrne's post gained attention online. The remedy is reportedly being prepared for a future major iOS 26 release.
Byrne described the issue publicly on Reddit, drawing broader attention to the iOS 26 passcode bug affecting users with certain Czech keyboard characters in their passcodes. His social media post helped surface the problem beyond his individual case.
University student Connor Byrne reported that his iPhone 13 became inaccessible because his passcode included the caron/háček character that disappeared from the lock-screen keyboard after the upgrade. The only built-in recovery option was restoring the device and losing locally stored data, so he remained locked out.
After iOS 26 shipped in September 2025, a Czech keyboard character used in some custom alphanumeric passcodes was no longer available on the iPhone lock-screen keyboard. This created a bug that could prevent affected users from entering their existing passcodes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.