Apple patches CoreGraphics zero-day CVE-2026-86950 exploited in targeted attacks
Apple has fixed an out-of-bounds write in Core Graphics that could give code execution from a malicious file. Apple says it may have been used in an "extremely sophisticated attack" on specific individuals, and CISA has added it to KEV.
Pixel 9 0-Click Exploit Chain: Dolby Codec Bug Meets AI Transcription
Google Project Zero chained an integer overflow in Dolby's audio decoder with a kernel driver flaw to get zero-click code execution on a Pixel 9 — reached through the auto-transcription feature in Google Messages.
Pixel's 0-Click Chain, Part 3: What Google Learned About Android Patching
Project Zero's own 0-click exploit chain against Pixel 9 took just weeks to build — but fixing the two bugs behind it took over four months and exposed real cracks in how Android's supply chain patches shared components.
Google's 2025 Play Store Numbers Show the Scale of the Mobile Threat Problem
Google's year-in-review disclosure — 1.75 million apps blocked pre-publication, 872,000 high-risk apps neutralized, and a new developer verification regime — is as much a map of attacker activity as it is a scorecard.