Apple CoreGraphics Vulnerability
Apple patched CVE-2026-86950 on September 28, 2026, crediting Meta Product Security with discovering the flaw.
According to Apple's security advisory, processing a maliciously crafted file could lead to arbitrary code execution. Apple also said it was aware of a report that the vulnerability may have been exploited in an extremely sophisticated attack against specific targeted individuals using versions of iOS before iOS 27.
The vulnerability is classified as an out-of-bounds write in Apple's CoreGraphics framework.
CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on September 29, with federal agencies required to apply the available security updates by October 2, 2026.
Researchers Reverse Engineer the Vulnerability
Researchers Dion Blazakis, Josh Maine, and Anna Groza from Calif analyzed the differences between iOS 26.7 and iOS 26.7.1 to determine how Apple fixed the vulnerability.
CoreGraphics handles graphics rendering, text drawing, image processing, and PDF-related operations across Apple's platforms.
The researchers found that the security update modified code used by multiple rasterizer functions. The affected code converts floating-point glyph coordinates into fixed-point values.
Before the fix, certain out-of-range coordinate values could be handled incorrectly.
This could cause CoreGraphics to calculate an incorrect bounding box for a glyph and allocate a buffer that was too small for the data that needed to be rendered.
The resulting operation could write data beyond the allocated memory region.
Malicious PDF Triggers the Vulnerability
To reproduce the vulnerability, the researchers created a specially crafted TrueType font with extremely large coordinate values.
The font was embedded inside a PDF and combined with:
- Crafted glyph coordinates
- PDF text-matrix transformations
- Nested composite-glyph scaling
- Specially constructed font-rendering operations
When the PDF was processed, the malformed font triggered the memory corruption.
The researchers also created a test harness that uses the ImageIO thumbnail-processing path used when applications generate previews for attachments.
According to Calif, the crash can be reproduced on both macOS and iOS. The published analysis includes a debugger stack trace for the macOS crash.
Public PoC Does Not Demonstrate Code Execution
The proof-of-concept demonstrates a controlled out-of-bounds write affecting attacker-controlled memory.
However, the researchers have not demonstrated a complete exploit that achieves arbitrary code execution.
Turning the memory corruption into reliable code execution would require additional exploitation techniques.
The researchers also said they did not obtain the original exploit sample used in the reported attacks. As a result, they cannot determine exactly how the attacker completed the exploitation chain.
Possible WhatsApp Connection
Because Meta Product Security was credited with discovering CVE-2026-86950, Calif also investigated whether WhatsApp could have been involved in delivering malicious PDF files.
The researchers compared WhatsApp versions 26.37.73 and 26.38.74 and identified changes in the application's Kaleidoscope attachment scanner.
The newer version checks PDF files for embedded font streams and can flag suspicious fonts using three classifications:
MalformedFontProgramUndecodableFontProgramUnverifiedFontProgram
Files receiving these classifications are given a high-risk score and prevented from being automatically parsed by the attachment checker.
Calif described these changes as circumstantial evidence that WhatsApp could potentially have been relevant to the delivery of the vulnerability.
However, the published research does not demonstrate a confirmed WhatsApp exploitation chain for CVE-2026-86950.
An earlier statement describing a specific WhatsApp delivery scenario was later removed from the researcher's publication.
Exact Attack Chain Remains Unknown
The researchers have not identified how the vulnerability was delivered in the attacks referenced by Apple.
There is currently no public information identifying:
- The attackers
- The number of victims
- The original exploit payload
- The exact delivery mechanism
- Whether WhatsApp was used
- Whether additional vulnerabilities were chained with CVE-2026-86950
The researchers also said they did not obtain the in-the-wild exploit sample.
Apple Security Updates
Apple released security updates addressing CVE-2026-86950, including:
- iOS 26.7.1
- iPadOS 26.7.1
- macOS Tahoe 26.7.1
- macOS Sequoia 15.8.1
Apple's advisory lists the affected iPhone, iPad, and Mac versions and recommends installing the available security updates.
Key Takeaway
CVE-2026-86950 is an Apple CoreGraphics out-of-bounds write vulnerability that has been linked to targeted attacks and now has a publicly available proof-of-concept.
The PoC demonstrates that a specially crafted PDF containing a malicious font can trigger memory corruption on vulnerable Apple devices. However, the published research does not demonstrate full code execution, and the exact attack chain used in the reported attacks remains unknown