{"ok":true,"trend":{"id":463422,"platform":"mastodon","region":"global","key":"🤖 apple patches cve-2026-86950: coregraphics out-of-bounds write allowing code execution from a crafted file. exploited","title":"🤖 Apple patches CVE-2026-86950: CoreGraphics out-of-bounds write allowing code execution from a crafted file. Exploited","url":"https://infosec.exchange/@cloud/117359038156065942","first_seen":"2026-09-30T08:47:47.944230Z","last_seen":"2026-09-30T08:47:47.944230Z","last_rank":9,"peak_rank":9,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.853125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Apple has patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics that could allow code execution when a device processes a maliciously crafted file. The flaw was reportedly exploited in an 'extremely sophisticated' attack targeting specific individuals on iOS versions before 27. It was reported by Meta Product Security and has been added to CISA's Known Exploited Vulnerabilities catalog, with a remediation deadline of October 2.","why":"The flaw was actively exploited against targeted individuals, and CISA has set an urgent patch deadline of October 2.","tone":"neutral","entities":["Apple","Meta","CISA","iOS","CoreGraphics"],"summarized_at":"2026-09-30T08:49:15.340201Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1282},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Apple patches actively exploited CoreGraphics flaw in iOS","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T08:47:47.944230Z","rank":9,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cloud/117359038156065942","author":"cloud@infosec.exchange","title":null,"snippet":"🤖 Apple patches CVE-2026-86950: CoreGraphics out-of-bounds write allowing code execution from a crafted file. Exploited in an \"extremely sophisticated\" attack against targeted individuals on iOS before 27. Added to CISA KEV (fix by Oct 2). Reported by Meta Product Security. 🔗…","posted_at":"2026-09-30T08:26:47Z","likes":1}],"elsewhere":[],"window":"7d"}}