Update your iPhone now to fix this critical security flaw

Same goes for iPad.
 By 
Stan Schroeder
 on 
Apple iPhone hack
The flaw was actively exploited in the wild. Credit: Getty Images

Apple has released iOS 16.6.1 and iPadOS 16.6.1, fixing two extremely dangerous security flaws in its mobile operating systems.

One flaw fixes an issue in which "processing a maliciously crafted image may lead to arbitrary code execution." Apple says it's aware of a report that this issue, which affects all newer iPhones and iPads, may have been actively exploited in the wild, which makes it the worst kind of security flaw.

The bug was found by the University of Torontoʼs Munk School security research facility Citizen Lab, which shared some more info on how it works and who's affected. Apparently, this exploit (which Citizen Lab named the Blastpass Exploit Chain) was capable of compromising iPhones running the latest version of iOS (16.6). Worse, it could do this without any interaction from the victim.


You May Also Like

The flaw was found while checking the device owned by a person employed by a civil society organization based in Washington DC. On their device, the vulnerability was use to deliver the notorious Pegasus spyware.

The new iOS 16.6.1 patch fixes another critical bug, which also may have been actively exploited. It affects newer iPhones and iPads, and it also meant a hacker could take over someone's phone by sending them a maliciously crafted attachment.

You can (and should) update your devices now by going to Settings - General - Software Update.

Topics Cybersecurity

Stan Schroeder
Stan Schroeder
Senior Editor

Stan is a Senior Editor at Mashable, where he has worked since 2007. He's got more battery-powered gadgets and band t-shirts than you. He writes about the next groundbreaking thing. Typically, this is a phone, a coin, or a car. His ultimate goal is to know something about everything.

Mashable Potato

Recommended For You
Homeland security pushes social media giants to dox anonymous accounts critical of ICE
By Jack Dawes
Ice Police Law Enforcement - Department of Homeland Security, Immigration and Customs Agents - stock photo

iOS 26.4 available now: All updates, security improvements to know
The Apple logo appears on a mobile phone screen in this photo illustration

Updating your security mindset: Keep your data private and your devices secure
By PCMag
Cyber Security

Update now: Apple iOS 26.2.1 arrives with support for AirTags 2
screenshot of software update screen in iphone settings menu

Score a free Apple iPhone 17e from T-Mobile — how to claim your free iPhone this weekend
the apple iphone 17e in several colorways in a row, overlapping each other in front of a green background

More in Tech
How to watch Chelsea vs. Port Vale online for free
Alejandro Garnacho of Chelsea reacts

How to watch 'Wuthering Heights' at home: Margot Robbie and Jacob Elordi's controversial romance now streaming
Margot Robbie and Jacob Elordi embracing in still from "Wuthering Heights"

How to watch New York Islanders vs. Philadelphia Flyers online for free
Matthew Schaefer of the New York Islanders warms up

How to watch Mexico vs. Belgium online for free
Israel Reyes of Mexico reacts

How to watch Brazil vs. Croatia online for free
Vinicius Junior #10 of Brazil leaves

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Wordle today: Answer, hints for April 2, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

You can track Artemis II in real time as Orion flies to the moon
Victor Glover and Reid Wiseman piloting the Orion spacecraft
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!