Cybersecurity News • 2h
Apple CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks
In late September 2026 Apple disclosed CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework triggered by a malicious PDF containing a crafted embedded font, enabling arbitrary code execution on unpatched iOS (<27) and macOS (Ventura <13.6, Monterey <12.7, Big Sur <11.7). The flaw was actively exploited in highly targeted attacks against high-value individuals. Emergency updates were released; public PoC appeared shortly after. Impact includes full device compromise, data exfiltration, and persistence.