Apple Issues Urgent Warning to iPhone Users Amid Active Mercenary Spyware Attacks
In early January 2026, Apple has heightened alerts regarding sophisticated mercenary spyware campaigns targeting iPhone users. These advanced threats exploit previously unknown vulnerabilities, prompting the company to emphasize the critical need for immediate software updates.
The issue stems from two critical zero-day flaws in WebKit—the browser engine powering Safari and many other iOS features. Apple patched these vulnerabilities (including a use-after-free issue and a memory corruption flaw) on December 12, 2025, confirming they were actively exploited in the wild. The company stated that the flaws “may have been exploited in an extremely sophisticated attack against specific targeted individuals” on iOS versions prior to iOS 26.
Mercenary spyware refers to highly expensive, custom-developed surveillance tools often linked to state actors or private firms (similar to NSO Group’s Pegasus). These attacks are typically zero-click, meaning they require no user interaction—such as clicking a link—to compromise a device. They are rarely aimed at everyday users and instead focus on high-profile targets like journalists, activists, politicians, diplomats, and other individuals due to their status or activities. Since 2021, Apple has issued threat notifications to affected users in over 150 countries.
While the initial exploits appear narrowly targeted, security experts warn that such vulnerabilities can lead to broader risks if left unpatched. Reports indicate that hundreds of millions of iPhones—potentially up to half of the global user base—are still running older versions without these fixes, as adoption of iOS 26 has been slower than expected. Devices older than the iPhone 11 lack access to the necessary patches entirely.
Apple’s official threat notifications, sent via email, iMessage, or displayed on the user’s Apple ID page, carry high-confidence warnings. A typical message informs the recipient that their device is being targeted by mercenary spyware attempting remote compromise. These alerts are rare and reserved for confirmed cases.
To protect against these threats, Apple strongly recommends the following steps:
- Update immediately to the latest iOS version (iOS 26 or newer, including security releases like iOS 26.2). Go to Settings > General > Software Update on your iPhone.
- Restart your device after updating, as this can help clear potential in-memory threats.
- Enable Lockdown Mode if you suspect you are at elevated risk. This optional, extreme protection feature restricts certain functionalities (such as message attachments and web technologies) to minimize the attack surface. Access it via Settings > Privacy & Security > Lockdown Mode.
Additional general best practices include using strong, unique passcodes, enabling two-factor authentication, installing apps only from the App Store, and avoiding unsolicited links or attachments. Apple emphasizes that most people will never encounter these rare, resource-intensive attacks.
For those receiving an official notification, Apple advises seeking expert assistance, such as through organizations like Access Now’s Digital Security Helpline. Regular software updates remain the most effective defense against evolving cyber threats.
Stay vigilant—keeping your iPhone current is one of the simplest yet most powerful ways to safeguard your privacy and security in an era of increasingly advanced digital surveillance.