Public CoreGraphics PoC Raises Pressure to Patch Apple Devices Under Targeted Attack
Public PoC for CVE-2026-86950 confirms CoreGraphics font crash, raising pressure to patch iOS 26.7.1 and macOS amid targeted attacks.
Illustrative image generated with AI
Researchers demonstrate a controlled memory write, not full code execution
Security researchers have released the first public proof of concept for CVE-2026-86950, an Apple CoreGraphics vulnerability triggered by malicious font data embedded in a PDF.
The proof of concept causes affected systems to crash and demonstrates a controlled out-of-bounds write. It does not provide a complete exploit or show arbitrary code execution.
That distinction matters. The research establishes a usable memory-corruption primitive, while additional work would be required to turn it into a reliable exploit chain. NVD nevertheless records arbitrary code execution as a potential consequence of processing a maliciously crafted file.
Apple has said the vulnerability may have been used in an “extremely sophisticated attack” against specific individuals running iOS versions earlier than iOS 27. The reporting does not identify the attacker, the targeted users, or the mechanism used to deliver and exploit the file.
The flaw carries a CVSS v3 score of 8.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. NVD classifies it as CWE-787, an out-of-bounds write.
The vector describes a network-reachable issue with low attack complexity, no required privileges, and some user interaction. Successful exploitation could have a high impact on confidentiality, integrity, and availability without changing the security authority represented by the affected component.
Faulty glyph conversion leads to an undersized buffer
Dion Blazakis, Josh Maine, and Anna Groza of Calif published their analysis on September 30. They began by comparing the public binaries for iOS 26.7 and iOS 26.7.1.
According to their findings, CoreGraphics was the only library changed in the updated release. The same correction appeared more than 20 times across eight rasterizer functions, indicating that Apple applied the fix at multiple points where font geometry is processed.
The underlying problem arises while CoreGraphics converts a glyph coordinate from floating-point form into a 32-bit fixed-point value. Before the patch, two of the eight relevant functions treated coordinates outside the valid range differently. One saturated the result, while the other truncated it.
That inconsistency could make the calculated bounding box for a glyph smaller than the space actually needed during rendering. CoreGraphics would then allocate an insufficient working buffer and write beyond its boundary.
To reproduce the condition, the researchers built a TrueType font containing coordinates large enough to produce the overflow. They embedded that font in a PDF and used a text matrix together with nested composite-glyph scaling to reach the vulnerable calculations.
Calif released generation scripts and a sample PDF in a public GitHub repository. Its test harness exercises the ImageIO thumbnail-processing route used when an application generates a preview for a received attachment.
The researchers reported crashes on both macOS and iOS. Their publication includes a complete debugger call stack for the macOS crash, although it does not provide a separate trace for the iOS result.
The resulting primitive allows controlled corruption of two adjacent 16-bit values in an attacker-influenced buffer. Calif said this could potentially be developed into writes affecting stack or heap memory. The researchers did not demonstrate that final step or execute attacker-supplied code.
Apple updates cover iOS, iPadOS, and two macOS releases
Apple issued fixes on September 28, according to The Hacker News’ reporting. NVD identifies the corrected releases as:
- iOS 26.7.1
- iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1
NVD’s affected-product records list:
apple iphone os < 26.7.1apple ipados < 26.7.1apple macos < 15.8.1
There is a scope inconsistency in those entries. The macOS affected-version field stops at versions earlier than 15.8.1, while the fix description separately includes macOS Tahoe 26.7.1. The available material does not reconcile those two records.
Apple’s advisories did not list iOS 27 or macOS Golden Gate 27 as affected. That aligns with Apple’s statement limiting the reported targeted exploitation to iOS versions before iOS 27, but it does not reveal which releases were used by the targeted individuals.
For affected devices, installing the applicable Apple update is the direct remediation. No workaround was described for systems that cannot be updated immediately.
Reported exploitation lacks a public sample or attribution
Apple said it knew of a report that CVE-2026-86950 may have been exploited against a small, targeted population. Calif did not obtain the file used in those attacks and could not determine how an attacker completed the broader exploit chain.
No attacker has been named in the supplied reporting. It also provides no network indicators, payload names, malicious file hashes, or other identifiers that defenders could use to locate the reported exploit directly.
The public proof of concept should therefore not be treated as a reproduction of the in-the-wild attack. It demonstrates the underlying CoreGraphics defect and a controlled write primitive, but it does not establish the original delivery route or the remaining exploitation stages.
CISA’s decision to include the vulnerability in its Known Exploited Vulnerabilities catalog gives the issue immediate operational significance. It does not, by itself, fill the gaps concerning attribution, victims, or technical execution.
WhatsApp changes are suggestive but do not establish delivery
Calif examined WhatsApp because Apple credited Meta Product Security with finding the vulnerability. Its comparison of WhatsApp versions 26.37.73 and 26.38.74 found new PDF inspection logic in the newer release’s Kaleidoscope attachment scanner.
That code checks PDFs for embedded font streams and can apply three defect labels:
MalformedFontProgramUndecodableFontProgramUnverifiedFontProgram
Any of those labels raises the attachment to a high-risk score. WhatsApp’s attachment checker then stops automatically parsing the flagged file.
These changes are circumstantial evidence that Meta strengthened handling of PDFs containing questionable fonts. They do not prove that WhatsApp delivered the malicious document used in Apple’s reported attacks.
Calif discussed the possibility of a WhatsApp zero-click route but did not describe or test one. An early version of its analysis also suggested that opening a chat from a trusted contact, with automatic media downloads enabled, might trigger the issue. Calif CEO Thai Duong removed that sentence 85 minutes after publication, describing the edit as the removal of WhatsApp speculation.
The remaining research raises the possibility that other WhatsApp vulnerabilities could have helped a file reach the vulnerable parser with less interaction. That remains an open question, not an established exploit chain.
WhatsApp had not published an advisory connecting CVE-2026-86950 to its products, and Meta did not answer questions about possible involvement before publication. A separate incident from August 2025 involved a WhatsApp linked-device synchronization flaw reportedly combined with another Apple out-of-bounds write against fewer than 200 users. No connection to CVE-2026-86950 has been established.
CISA’s federal remediation deadline is October 2
CVE-2026-86950 entered CISA’s KEV catalog on September 29, 2026. U.S. federal agencies have a remediation deadline of October 2, 2026.
CISA directs agencies to apply vendor mitigations while complying with BOD 26-04, Prioritizing Security Updates Based on Risk, and its Forensics Triage Requirements. Its action also calls for applicable BOD 26-04 guidance to be followed for cloud services, or for affected products to be discontinued when mitigations are unavailable. Agencies are responsible for evaluating each asset’s internet exposure and following the directive’s patching requirements.
This is also Apple’s second KEV addition within 90 days. CVE-2026-65400 entered the catalog on August 18, 2026.
Organizations managing Apple fleets should identify devices below the fixed versions and deploy the relevant updates. The absence of a documented workaround leaves patching as the available corrective action in the supplied guidance. Apple has not said whether Lockdown Mode would have stopped the delivery mechanism used in the reported attacks.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-65400Critical9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
- CVE-2026-86950High8.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have bee




