Proof‑of‑Concept for Apple CoreGraphics Flaw Published
🛡️ Researchers published a public proof‑of‑concept for CVE‑2026‑86950, an Apple CoreGraphics vulnerability Apple says may have been used in targeted attacks. The trigger is a malicious PDF with a crafted embedded font that causes a crash on unpatched iPhones and Macs, though the published code demonstrates a crash, not full code execution. Apple patched the flaw on September 28 after crediting Meta Product Security, and CISA added it to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 2.
