{"ok":true,"trend":{"id":599256,"platform":"mastodon","region":"global","key":"🤖 cve-2026-86950 (apple coregraphics): first public poc published. a malicious pdf with a crafted embedded font crashes","title":"🤖 CVE-2026-86950 (Apple CoreGraphics): first public PoC published. A malicious PDF with a crafted embedded font crashes","url":"https://infosec.exchange/@cloud/117364787924692034","first_seen":"2026-10-01T10:47:26.870821Z","last_seen":"2026-10-01T10:47:26.870821Z","last_rank":9,"peak_rank":9,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.853125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A first public proof-of-concept is now available for CVE-2026-86950, a vulnerability in Apple's CoreGraphics. A malicious PDF with a crafted embedded font crashes unpatched iPhones and Macs, though no working exploit has been demonstrated. Apple patched the flaw on September 28 after targeted attacks, and CISA set an October 2 fix deadline for federal agencies under its Known Exploited Vulnerabilities catalog.","why":"The release of a public PoC shortly after the patch deadline raises concern that more attackers may now weaponise the flaw.","tone":"neutral","entities":["Apple","CoreGraphics","CISA","CVE-2026-86950"],"summarized_at":"2026-10-01T10:49:30.505026Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1291},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Public PoC Released for Apple CoreGraphics Flaw","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-01T10:47:26.870821Z","rank":9,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@cloud/117364787924692034","author":"cloud@infosec.exchange","title":null,"snippet":"🤖 CVE-2026-86950 (Apple CoreGraphics): first public PoC published. A malicious PDF with a crafted embedded font crashes unpatched iPhones/Macs — crash only, no working exploit demonstrated. Apple patched Sep 28 after targeted attacks; CISA KEV fix deadline Oct 2. 🔗 https://…","posted_at":"2026-10-01T08:49:02Z","likes":1}],"elsewhere":[],"window":"7d"}}