Published: · Region: Global · Category: cyber

Apple CoreGraphics Flaw and Bitget Theft Show How Core Tools Become Attack Paths

A critical Apple CoreGraphics bug that can be triggered by a malicious PDF and a $387.5 million theft from crypto exchange Bitget via a third‑party zero‑day reveal how attackers are abusing widely trusted software and security products.

Two disclosures on 1 October highlight a sharp risk for high‑value targets: attackers are increasingly going after the software and security tools that sit deep inside everyday systems.

In one case, Apple has detailed a serious vulnerability in its CoreGraphics component, tracked as CVE‑2026‑86950. The company says a malicious PDF can trigger controlled memory corruption and that the flaw may already have been used in targeted attacks. A public proof‑of‑concept exploit has now been released, which raises the likelihood that others will try to incorporate the bug into broader campaigns.

CoreGraphics underpins how Apple devices handle images and documents, so the issue reaches beyond any single app. Security watchers have noted that checks inside WhatsApp for PDF files hint at a possible delivery route, though that vector remains unconfirmed. The concern is that a routine‑looking document could be enough to give an attacker a foothold on a device packed with personal and corporate data.

Separately, crypto exchange Bitget has confirmed that attackers stole $387.5 million after exploiting a previously unknown vulnerability in a third‑party security product used by the platform. Incident response firm Mandiant found that the intruders compromised security appliances, then moved laterally into Bitget’s wallet environment and deployed malicious packages on the wallet job server.

In this case, the very devices meant to provide protection became the entry point. By using a zero‑day vulnerability in a trusted security product, the attackers were able to reach systems handling large volumes of digital assets.

The two cases sit alongside other recent research pointing to how attackers work around passwords and traditional malware. Demonstrations of malicious OAuth applications show how a single click on a consent screen can grant broad access to an email inbox, allow quiet data exfiltration and enable movement deeper into an organization. Analysis of Citrix NetScaler compromises has described second‑stage payloads that create superuser accounts and hide PHP web shells behind URLs that look like harmless CSS paths, with scripts that erase themselves after use.

Taken together, these incidents show how both end‑user actions and deeply embedded infrastructure can be turned against organizations.

Key developments to track will be the pace of Apple’s patch roll‑out, signs that CVE‑2026‑86950 is being used in wider attacks, more technical detail on the third‑party product involved in the Bitget breach, and any indications that other organizations using similar tools are being probed in the same way.

Sources