Skip to content
feed: live
>_0dayNews
apple
● Breaking

Apple CoreGraphics PoC Released, KEV Deadline Oct 2

A public PoC for CVE-2026-86950 is available as of October 1. CISA's patch deadline for federal agencies is October 2. Affected: iOS 26, iPadOS, macOS 26, macOS 15.

Apple CoreGraphics PoC Released, KEV Deadline Oct 2
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Public proof-of-concept for CVE-2026-86950 is now circulating. First published October 1, per The Hacker News. The flaw is a memory safety issue in Apple CoreGraphics. CVSS 8.8, high severity, NVD-verified.

CISA added CVE-2026-86950 to the Known Exploited Vulnerabilities catalog on September 29. Federal agency remediation deadline: October 2. That is tomorrow.

What’s confirmed

CVE-2026-86950 is an out-of-bounds write in Apple’s CoreGraphics framework, per NVD and Dark Reading. Apple patched it September 28 with emergency updates for iOS 26, iPadOS, macOS 26, and macOS 15. Apple’s advisory language: “may have been exploited in targeted attacks against specific individuals.” That language reflects confirmed or strongly suspected pre-patch exploitation, per the company’s standard advisory practice.

As of October 1, a public PoC is available. Reporting: The Hacker News. This article does not reproduce exploit code or weaponization steps; see those primary sources for researcher-level technical detail.

Status as of October 1, 2026:

  • Patch available: yes, September 28
  • CISA KEV: confirmed September 29, federal deadline October 2
  • Active exploitation: confirmed by Apple, pre-patch targeting
  • PoC status: public, as of October 1

WhatsApp PDF delivery path: Analysis, unconfirmed

Researchers examining the flaw noted behavior in WhatsApp’s PDF handling as a potential delivery mechanism, per The Hacker News. Analysis: this is an emerging research hypothesis. Not confirmed by Apple, CISA, or any named incident responder as of this writing. No documented attacks using this delivery path. Treat accordingly.

Patch

iOS 26, iPadOS, macOS 26, and macOS 15 updates released September 28 address CVE-2026-86950. Apply them. CISA’s KEV guidance is binding for federal agencies; private-sector organizations should treat KEV additions as a prioritized patching signal.

Full vulnerability details: CVE-2026-86950.

Prior coverage

Related CVEs
  • [ HIGH ]CVE-2026-86950CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15

Found this useful? Share it.