Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw that Apple says may have been used in attacks against specific targeted individuals, and the trigger is a malicious PDF with a crafted embedded font.
The flaw crashes unpatched iPhones and Macs, and the code causes a crash rather than an execution error, so turning that memory corruption into a working exploit is separate work that the analysis does not demonstrate.
Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories, and no workaround has been described for systems that cannot update immediately.
Quick Summary
|
What |
Details |
|
Flaw |
CVE-2026-86950 |
|
Framework |
Apple CoreGraphics |
|
Trigger |
Malicious PDF with embedded font |
|
Impact |
Crash, memory corruption primitive |
|
Patched |
September 28, 2026 |
|
CISA Deadline |
October 2, 2026 |
|
Discovered By |
Meta Product Security |
|
PoC Published By |
Calif |
What the Researchers Found
The analysis was published September 30 by Dion Blazakis, Josh Maine, and Anna Groza of Calif, a firm known for research into zero-click attack surfaces in messaging apps, and they started from a publicly available binary comparison of iOS 26.7 and 26.7.1.
CoreGraphics is the Apple framework for 2D drawing, image rendering, and PDF processing, and it was the only library changed in 26.7.1, with the same fix applied more than 20 times across eight rasterizer functions.
The patched code converts a glyph coordinate from floating-point to a 32-bit fixed-point value, and before the patch, two of the eight functions handled out-of-range values differently, with one saturating the result and the other truncating it.
That difference caused the calculated bounding box for a glyph to be too narrow, so CoreGraphics allocated a working buffer smaller than the edges it needed to draw, and wrote outside it.
To trigger the bug, the researchers built a TrueType font with coordinates large enough to force the overflow, embedded it in a PDF with a text matrix and nested composite-glyph scaling, and pushed those coordinates past the limit, and they published the generation scripts and a sample PDF in a public GitHub repository.
The harness calls the same ImageIO thumbnail path an app uses when previewing a received attachment, and the researchers say the crash occurs on both macOS and iOS, though the macOS result includes a full debugger call stack while the iOS claim is Calif's with no separate trace published.
The crash exposes a controlled out-of-bounds write that affects two adjacent 16-bit values in a buffer that the attacker can control, allowing writes to the stack or heap, and Calif says converting that primitive into working code execution is separate work, and the firm did not obtain the in-the-wild sample and cannot say how the attacker completed the chain.
The WhatsApp Question
Calif examined WhatsApp because Meta Product Security was credited with finding the flaw, and the firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp's Kaleidoscope attachment scanner.
The newer version reads PDF files for embedded font streams and flags suspicious ones with three defect tags, which are MalformedFontProgram, UndecodableFontProgram, and UnverifiedFontProgram, and any such tag returns a high-risk score to WhatsApp's attachment checker, which then stops automatic parsing of the flagged file.
Calif described those changes as circumstantial evidence pointing toward WhatsApp as a possible delivery vector, and the firm's post describes its research as covering a possible WhatsApp zero-click path, though the published analysis does not describe or test a WhatsApp delivery path.
The initial version did, because it said the researchers' analysis suggested WhatsApp could deliver a PDF that triggers the flaw when a victim opens a chat from a trusted contact with automatic media downloads on, but that sentence was removed 85 minutes after publication in a commit by Calif CEO Thai Duong, who described the change as removing the WhatsApp speculation.
The analysis closes with a question, asking whether the flaw was combined with additional vulnerabilities in WhatsApp to reach parsing with less user interaction, and that phrasing suggests the path Calif studied would require user action or further WhatsApp vulnerabilities in the chain.
WhatsApp has published no advisory linking this flaw to its products, and its 2026 advisory page lists two unrelated vulnerabilities, and The Hacker News asked Meta whether WhatsApp was involved in the reported attacks, though Meta did not respond before publication.
An earlier case makes the hypothesis plausible, because in August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users.
The Hacker News asked Calif about the removed delivery claim and whether the researchers had obtained the in-the-wild sample since publication, and Calif did not respond before publication, and no network indicators, attacker identifiers, or exploit payload names have been made public, and Apple has not said whether Lockdown Mode would have blocked the delivery path used in the reported attacks.
What You Should Do
- Update to the latest iOS and macOS versions immediately, because Apple patched CVE-2026-86950 on September 28.
- Treat any PDF attachment from an unknown or unexpected sender as suspicious, especially if it comes through a messaging app with automatic media downloads enabled.
- Consider disabling automatic media downloads in WhatsApp and similar apps, because that reduces the chance of a malicious file being parsed without your knowledge.
- If you are a high-risk individual, enable Lockdown Mode on your Apple devices, though Apple has not confirmed whether it blocks this specific delivery path.
- Monitor for unusual crashes in PDF viewers or preview handlers, because the proof-of-concept triggers a crash rather than silent execution.
- Watch for updates from Apple and Meta as more details about the in-the-wild attacks emerge.
- If you are a federal agency, meet the October 2 CISA deadline.
The Bottom Line
The first public proof-of-concept for CVE-2026-86950 shows how a malicious PDF with a crafted embedded font can crash unpatched iPhones and Macs, and while the analysis stops at the crash and does not demonstrate full code execution, the flaw was serious enough for Apple to patch it and for CISA to add it to the KEV catalog, so if you have not updated your Apple devices, do it now, and treat PDF attachments with the caution they deserve.
Quick Reference
|
Key Point |
Detail |
|
Flaw |
CVE-2026-86950 |
|
Framework |
CoreGraphics |
|
Trigger |
PDF with embedded TrueType font |
|
Impact |
Crash and memory corruption primitive |
|
Patched |
September 28, 2026 |
|
CISA Deadline |
October 2, 2026 |
|
PoC |
Published by Calif on September 30 |
What to Do
- Update iOS and macOS
- Treat unexpected PDFs as suspicious
- Disable automatic media downloads
- Consider Lockdown Mode for high-risk users
- Monitor for unusual PDF viewer crashes
- Watch for Apple and Meta updates
- Meet the CISA deadline if applicable
FAQ Section
What is CVE-2026-86950?
It is a flaw in Apple's CoreGraphics framework that a malicious PDF with a crafted embedded font can trigger, causing a crash on unpatched iPhones and Macs.
Has it been exploited in the wild?
Apple says it may have been used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, and CISA added it to the KEV catalog.
What does the proof-of-concept demonstrate?
It shows that a crafted font embedded in a PDF can cause an out-of-bounds write and crash the device, but it does not demonstrate full code execution.
Is WhatsApp involved?
Calif found new font-scanning code in WhatsApp's Kaleidoscope attachment scanner, but the published analysis does not test a WhatsApp delivery path, and WhatsApp has published no advisory linking the flaw to its products.
What should I do to protect myself?
Update to the latest iOS and macOS versions, treat unexpected PDF attachments as suspicious, disable automatic media downloads, and consider Lockdown Mode if you are high-risk.
Is there a workaround if I cannot update?
Apple has not described a workaround for systems that cannot update immediately, so patching is the recommended action.