Back to News

Apple CoreGraphics CVE-2026-86950 PoC Triggers iOS and macOS Crashes via Malicious PDFs

Apple CoreGraphics CVE-2026-86950 PoC Triggers iOS and macOS Crashes via Malicious PDFs

An Apple CoreGraphics proof-of-concept for CVE-2026-86950 now publicly reproduces a crash caused by a crafted PDF with an embedded font, while Apple has warned that the flaw may have been used in a targeted attack. Apple released patches on September 28, and the Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog the next day with a federal remediation deadline of October 2. Researchers at Calif said their analysis suggests WhatsApp attachment scanning may relate to a possible delivery path, but the published material does not demonstrate that WhatsApp was used to deliver the exploit or that the crash can be converted into remote code execution.

Key Points

  • Apple patched a CoreGraphics flaw that can be triggered by a malicious PDF and credited Meta Product Security with discovering it.
  • Calif published a PoC that causes crashes on macOS and iOS, but it does not demonstrate a working code-execution exploit.
  • Changes in WhatsApp’s PDF attachment scanner suggest possible defensive handling of malicious fonts, but do not prove WhatsApp was the delivery method.
  • CISA added the vulnerability to its exploited-vulnerability catalog, making prompt patching important for affected devices.

What the vulnerability does

CVE-2026-86950 affects CoreGraphics, Apple’s framework for 2D drawing, image rendering and PDF processing. Apple credited Meta Product Security with discovering the issue, while Calif researchers Dion Blazakis, Josh Maine and Anna Groza published the technical analysis and public proof-of-concept.

Calif began its analysis with a binary comparison of iOS 26.7 and iOS 26.7.1 and found that CoreGraphics was the only changed library in that update. The researchers said the vulnerable code path involved converting glyph coordinates from floating-point values to 32-bit fixed-point values.

Before the patch, different rasterizer functions handled out-of-range values inconsistently. One function saturated the values while another truncated them, producing a bounding box that was too small and causing CoreGraphics to allocate a working buffer smaller than required. The resulting out-of-bounds write affected two adjacent 16-bit values in a controllable buffer, according to Calif, and the fix was applied more than 20 times across eight rasterizer functions.

For the PoC, the researchers created a TrueType font with extremely large coordinates and embedded it in a PDF. A text matrix and nested composite-glyph scaling push the coordinates beyond the conversion limit and trigger the memory corruption. Calif published generation scripts and a sample PDF with its analysis.

The test harness uses the ImageIO thumbnail and preview path, which is also used when an application previews an attachment. Calif produced a complete debugger call stack for the macOS crash and reported that the same technique crashes iOS, although it did not publish a separate iOS trace.

The crash provides a controlled out-of-bounds write, but it is not a complete exploit. Calif said the primitive could be developed into stack or heap writes, while turning it into reliable code execution would require separate work.

Apple and CISA response

Apple released fixes for affected Apple platforms on September 28. Apple also backported fixes to older operating-system branches, according to Security Arsenal, indicating that supported legacy releases were included in the remediation effort.

Apple described the potential exploitation in its advisory:

“may have been used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”

Apple

On September 29, the Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog. The addition triggered a federal remediation requirement with a deadline of October 2.

Calif published its detailed analysis on September 30. An initial sentence that directly speculated about a WhatsApp delivery path was removed 85 minutes after publication in a commit by Calif CEO Thai Duong.

Why WhatsApp was examined

Calif examined WhatsApp because Apple credited Meta Product Security with discovering the vulnerability. The researchers compared WhatsApp versions 26.37.73 and 26.38.74 and found changes in the newer version’s Kaleidoscope attachment scanner that inspect embedded font streams in PDF files.

The newer scanner flags suspicious font streams with the defect tags MalformedFontProgram, UndecodableFontProgram and UnverifiedFontProgram. When a stream is flagged, WhatsApp’s attachment checker assigns the file a high-risk score and stops automatic parsing.

Calif described those changes as circumstantial evidence that WhatsApp could have been a delivery vector, not as proof that it was used in an attack involving CVE-2026-86950. WhatsApp has not published an advisory linking the CoreGraphics vulnerability to its products, and The Hacker News reported that Meta had not responded to its query before publication.

A separate case from August 2025 provides context but does not establish the current delivery path. In that case, WhatsApp assessed an attack chain combining a WhatsApp vulnerability with a separate Apple out-of-bounds write that affected fewer than 200 targeted users.

What is known about exploitation

Calif did not obtain the alleged in-the-wild sample and cannot determine how attackers completed the exploitation chain. No public network indicators, attacker identifiers or exploit payload names have been released.

Security Arsenal recommends applying Apple’s security updates for affected iOS, iPadOS and macOS releases immediately, inventorying legacy devices that cannot run current operating-system versions and enforcing updates through mobile-device management. It also recommends prioritizing high-risk users such as executives, journalists and legal counsel, considering Lockdown Mode for those users, increasing telemetry for crashes and process lineage, and reviewing historical telemetry for possible activity before the patches were released.

Sources

Mayank Mehra

Written by

Mayank Mehra is a cybersecurity professional with 8+ years of hands-on experience in application security, penetration testing, vulnerability assessment, and AI security. He holds CEH, CAPEN, and CRTP certifications and specialises in identifying and mitigating security risks across applications and AI-powered systems.

View all posts →