I stumbled over two or three of them in the last couple of years while debugging crash reports sent in by customers.
Seems that text rendering is hard. Maybe fuzzing CoreText would be a worthwhile target to discover vulnerabilities?