← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO AI

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

Číst originál na BleepingComputer →

5 zpráv z 5 zdrojů · první CZ · EN/orig

Apple US IT FR

tg: zneužíváno tg: zranitelnost tg: novinka v produktu tp: špionáž

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-86950 8.8 3.1 · CISA-ADP – –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Tahle CVE jsem vytáhl z širšího textu článku: CVE-2025-14174, CVE-2025-20701, CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43529, CVE-2026-20700. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.

Jak se o tom psalo 5

  1. · Malwarebytes Labs US

    Update your iPhone, iPad, or Mac: Flaw could run attackers’ code

    Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27. The fix is in iOS and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Check Software Update on each of your Apple devices and install the latest version offered. Updates for your particular device The table…

  2. · CSIRT Itálie (ACN) IT

    Apple: rilevato sfruttamento in rete della CVE-2026-86950

    Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-86950 – già sanata dal vendor - che interessa i prodotti Apple iOS, iPadOS, macOS Tahoe e macOS Sequoia. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato l'esecuzione di codice arbitrario sui sistemi interessati.

  3. · BleepingComputer US nadpis události

    Apple patches CoreGraphics zero-day flaw exploited in attacks

    Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

  4. · zachyceno · CERT-FR – avis FR

    Vulnérabilité dans les produits Apple (29 septembre 2026)

    Une vulnérabilité a été découverte dans les produits Apple. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Apple indique que la vulnérabilité CVE-2026-86950 est activement exploitée.

  5. · SANS Internet Storm Ctr. US

    Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)

    Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will…