HomeSecurityCVE-2026-86950: PoC for critical Apple CoreGraphics vulnerability

CVE-2026-86950: PoC for critical Apple CoreGraphics vulnerability

The CVE-2026-86950 in Apple CoreGraphics is in the spotlight of the cybersecurity community, as researchers have published the first public proof-of-concept (PoC) exploit for the critical flaw. Apple had previously stated that the vulnerability could have been used in targeted attacks against specific individuals, and publishing the PoC significantly increases the risk for users who have not yet installed the latest security updates.

CVE-2026-86950 Apple CoreGraphics vulnerability proof-of-concept PDF exploit

The flaw is found in CoreGraphics, Apple's framework for 2D drawing, image rendering , and PDF processing. Its exploit relies on a malicious PDF containing a specially craftedTrueType, which causes a crash on unpatched iPhone and Mac. Importantly, the published PoC causes a crash rather than direct code execution — converting the memory corruption into a fully functional exploit is a separate step that has not been published.

Apple released the fix on September 28 , attributing the discovery to the Meta Product Security team . In the related announcements, the company said that the vulnerability could have been used in a “ highly sophisticated attack against specific targets in iOS prior to iOS 27. versions ” This wording suggests that it is a zero-day vulnerability exploited by state-sponsored or highly capable threat actors.

See also: CVE-2026-86950: Apple fixes zero-day discovered by Meta

CVE-2026-86950: What exactly did researchers find about Apple CoreGraphics

The analysis was published on September 30 by Dion Blazakis, Josh Maine , and Anna Groza of Calif., a company that specializes in zero-click on messaging apps. The researchers started with a publicly available binary comparison between iOS 26.7 and iOS 26.7.1, finding that CoreGraphics was the only library that changed, with the same fix applied in more than 20 places across eight rasterizer functions.

CVE-2026-86950 - SecNews.gr

The problem lies in the way the code converts the coordinates of a glyph (font character) from floating-point to a 32-bit fixed-point value. Before the fix, two of the eight functions handled out-of-range values ​​differently. This inconsistency resulted in the calculation of a bounding box for the glyph that was narrower than the actual one, causing CoreGraphics to allocate a smaller work buffer than needed to draw the edges of the character — and ultimately write outside its bounds.

To trigger the bug, the researchers crafted a TrueType font with coordinates large enough to cause an overflow. Embedding it in a PDF with the appropriate text matrix and nested composite-glyph scaling pushes the coordinates beyond the allowable limit. The researchers published the creation scripts and a sample PDF to a public GitHub repository. The crash occurs on both macOS and iOS, with the macOS result including a full stack trace from a debugger.

CVE-2026-86950 and WhatsApp

One of the most interesting points of the research concerns the connection to WhatsApp . Since Meta Product Security was credited with discovering the vulnerability , Calif examined two recent versions of the app: 26.37.73 and 26.38.74 . In the newer version, they found new code in WhatsApp 's Kaleidoscope attachment scanner .

Specifically, the newer version reads PDF looking for embedded font streams and flags suspects with three labels: MalformedFontProgram, UndecodableFontProgram , and UnverifiedFontProgram. Any of these labels returns a high risk score to WhatsApp’s attachment checker, which then stops automatic analysis of the flagged file. Calif described these changes as “circumstantial evidence” that points to WhatsApp as a possible delivery vehicle for the attack.

See also: CVE-2026-16232: PoC for Check Point SmartConsole critical vulnerability

The scenario described is particularly concerning: a malicious PDF could be delivered via WhatsApp and trigger the vulnerability when the victim opens a conversation from a trusted contact with automatic media download enabled. However, the published analysis does not describe or test a full delivery path via WhatsApp — this is a hypothetical scenario based on circumstantial evidence.

CISA's response and the impact of CVE-2026-86950 on Apple CoreGraphics

The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) the day after the patch was released, requiring federal agencies to implement the update by October 2.This speed reflects the severity of the threat and the belief that the vulnerability was actively exploited.

It is worth noting that Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in its September 28. Also, no workaround has been described for systems that cannot be updated immediately, which makes installing the security update the only reliable solution.

Article image: WhatsApp expands parental controls to teen accounts with group alerts, Meta AI restrictions

The fact that Calif did not obtain the sample used in the actual attack means that we do not know how the attacker completed the exploit chain. Converting the out-of-bounds write primitive into full code execution requires additional technical work, but for a capable threat actor with state-level resources, this is not an insurmountable obstacle.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Meta's Muse highlights new risk to Apple's revenue

For Apple device users, the recommendation is clear: immediately update to iOS 26.7.1 or later and the corresponding macOS. In addition, it is recommended to disable automatic media downloads in messaging apps such as WhatsApp, especially for users who consider themselves high-risk targets (journalists, activists, business executives). Avoiding opening PDF from unknown or unexpected sources is also a key security practice in this context.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS