iOS CoreGraphics PoC published two days after the patch
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics triggered by a malicious PDF font and used in targeted attacks on iOS before 27.
Apple patched CVE-2026-86950 on September 28, an out-of-bounds write in CoreGraphics that it says was used in “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” Meta Product Security reported it. CISA added it to the Known Exploited Vulnerabilities catalog the next day and gave federal agencies until October 2 to apply the fix.
The trigger is a malicious PDF with a crafted embedded font. Two days after the patch, Dion Blazakis, Josh Maine, and Anna Groza of Calif published the first public proof-of-concept, built from a binary diff of iOS 26.7 and 26.7.1. CoreGraphics was the only library that changed in that release, and the same fix appeared more than 20 times across eight rasterizer functions.
The root cause is an inconsistency in how those functions converted a glyph coordinate from floating-point to a 32-bit fixed-point value. Before the patch, two of the eight handled out-of-range input differently: one saturated the result, the other truncated it. That mismatch made the calculated bounding box for a glyph too narrow, so CoreGraphics allocated a working buffer smaller than the region it then drew into, and wrote past the end.
To force the overflow, the researchers built a TrueType font with coordinates large enough to blow past the limit, then embedded it in a PDF using a text matrix and nested composite-glyph scaling to push the numbers further. The resulting write is controlled: it hits two adjacent 16-bit values in a buffer the attacker can influence, landing on the stack or heap. The generation scripts and a sample PDF are in a public GitHub repository.
The PoC crashes unpatched iPhones and Macs through the same ImageIO thumbnail path an app uses to preview a received attachment. The macOS crash comes with a full debugger call stack; the iOS crash is Calif’s claim, with no separate trace published. Calif is explicit that turning this memory-corruption primitive into working code execution is separate work it did not demonstrate, and it did not obtain the in-the-wild sample, so it cannot say how the real attacker completed the chain.
The WhatsApp thread
Because Meta Product Security got the credit, Calif looked at WhatsApp. Comparing versions 26.37.73 and 26.38.74, it found new code in WhatsApp’s Kaleidoscope attachment scanner: the newer build reads PDFs for embedded font streams and tags suspicious ones as MalformedFontProgram, UndecodableFontProgram, or UnverifiedFontProgram. Any of those tags returns a high-risk score that stops automatic parsing of the file. Calif called that circumstantial evidence pointing to WhatsApp as a possible delivery vector.
The published analysis stops short of testing a WhatsApp path. An earlier version went further: it said the researchers’ analysis suggested WhatsApp could deliver a triggering PDF when a victim opened a chat from a trusted contact with automatic media downloads on. Calif CEO Thai Duong removed that sentence 85 minutes after publication, describing the edit as dropping WhatsApp speculation. What remains is a closing question about whether the flaw “was combined with additional vulnerabilities in WhatsApp to reach parsing with less user interaction,” phrasing that implies the path Calif studied would still need user action or more WhatsApp bugs.
WhatsApp has published no advisory linking its products to this flaw; its 2026 advisory page lists two unrelated issues. Meta did not answer The Hacker News’s question about WhatsApp’s involvement in the attacks, and Calif did not answer questions about the removed claim or whether it has since obtained the sample. The precedent exists: in August 2025 WhatsApp assessed that a flaw in its linked-device synchronization messages may have been chained with a separate Apple out-of-bounds write against fewer than 200 targeted users.
What to patch
The fix ships in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The affected device list is broad, covering iPhone 11 and later, recent iPad Pro, Air, mini, and base models from the 8th generation on, and Macs on Sequoia and Tahoe. Apple did not list iOS 27 or macOS Golden Gate 27 as affected.
There is no described workaround for systems that cannot update, and Apple has not said whether Lockdown Mode would have blocked the delivery path. With a crashing PoC and a sample PDF already public, the distance between that artifact and a working exploit is the only thing slowing wider use, so patch the moment you can. This is the second Apple zero-day exploited in the wild this year, after CVE-2026-20700 in dyld, patched in February.
Keep Reading
fortinetUnpatched FortiMail flaw under attack
Fortinet warns of CVE-2026-104286, a critical FortiMail flaw under active exploitation that lets unauthenticated attackers write arbitrary files.
cryptocurrencyAttackers drained $387.5M through Bitget's own security appliances
Bitget confirms a third-party zero-day let attackers reach its wallet job server and drain $387.5M; SlowMist and Mandiant trace the two-stage path.
netscalerCitrix patches second NetScaler SAML bug in days
Citrix patched NetScaler zero-day CVE-2026-88779, a SAML memory overflow under active attack that causes denial-of-service and may allow code execution.
Latest on the Wire
Full wire →- 16 Fake Firefox Extensions Stole Crypto Recovery PhrasesThe Hacker News
- AI Bolsters and Threatens Autocratic RegimesSchneier on Security
- AI Developer Launches Open-Source Adobe AlternativesArs Technica
- AI Helps Solve 15-Year Mystery of Obscure Band SalvageHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.