VMTech
Discuss a project →

Public CoreGraphics PoC Shows Crafted PDF Crash on Apple Devices

Public CoreGraphics PoC Shows Crafted PDF Crash on Apple Devices

Security researchers have released a public proof of concept for CVE-2026-86950, a vulnerability in Apple’s CoreGraphics framework that can crash unpatched iPhones and Macs when they process a malicious PDF containing a crafted embedded font. Apple fixed the issue on September 28 and said it may have been used in an “extremely sophisticated attack against specific targeted individuals” on versions of iOS before iOS 27.

The proof of concept, published on September 30 by Dion Blazakis, Josh Maine and Anna Groza of Calif, demonstrates a crash rather than code execution. Its authors state that converting the memory corruption into a usable exploit is separate work. Apple credited Meta Product Security with discovering the flaw.

How the CoreGraphics flaw is triggered

CoreGraphics handles 2D drawing, image rendering and PDF processing across Apple platforms. Calif compared the publicly available binaries for iOS 26.7 and iOS 26.7.1 and found that CoreGraphics was the only library changed in the latter release. The same correction appeared more than 20 times in eight rasterizer functions.

The affected code converts a glyph coordinate from floating point into a 32-bit fixed-point value. Before the update, two functions treated out-of-range values differently: one saturated the result while another truncated it. That mismatch could make a glyph’s calculated bounding box too narrow, causing CoreGraphics to allocate a buffer smaller than the area required for drawing and then write outside the buffer.

The researchers created a TrueType font with coordinates sufficiently large to provoke the overflow. A PDF embedding that font, together with a text matrix and nested composite-glyph scaling, drives the values beyond the limit. Calif published generation scripts and a sample PDF, using an ImageIO thumbnail-processing path that an application can invoke when previewing an attachment.

Calif reported crashes on macOS and iOS. Its macOS result includes a full debugger call stack, while its iOS result is a claim without a separately published trace. The firm describes a controlled out-of-bounds write affecting two adjacent 16-bit values in attacker-controlled memory, with possible writes to the stack or heap.

WhatsApp checks are not proof of a delivery chain

Calif also compared WhatsApp versions 26.37.73 and 26.38.74 because Meta Product Security received credit for the discovery. In the newer release, it found code in WhatsApp’s Kaleidoscope attachment scanner that reads PDFs for embedded font streams and assigns the tags MalformedFontProgram, UndecodableFontProgram and UnverifiedFontProgram. Any of those tags produces a high-risk score and stops automatic parsing of the file.

The researchers characterised this as circumstantial evidence of WhatsApp as a possible delivery vector, not confirmation. Their published analysis neither describes nor tests a WhatsApp delivery route. An initial claim about a potential zero-click path was removed 85 minutes after publication; Calif CEO Thai Duong said the edit removed WhatsApp speculation.

WhatsApp has not issued an advisory tying its products to CVE-2026-86950. No network indicators, attacker identities or exploit payload names have been released, and Apple has not said whether Lockdown Mode would have blocked the path used in the reported attacks.

Patch management is the immediate response

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on September 29 and required federal agencies to apply the fix by October 2. Apple’s September 28 advisories did not list iOS 27 or macOS Golden Gate 27 as affected, and no workaround has been described for devices that cannot be updated immediately.

For businesses, the practical action is to identify Apple endpoints that remain on affected releases, deploy Apple’s available security updates promptly, and ensure attachment-handling policies account for the risk from PDF files with embedded fonts while patch coverage is completed.

#cybersecurity#applesecurity#vulnerability#mobilesecurity
Open analytics
On the site 0 views
min read 4 01.10.2026
Instagram

Public CoreGraphics PoC Shows Crafted PDF Crash on Apple Devices

Open the post on Instagram ↗