Apple’s recently patched CoreGraphics vulnerability has received its first public proof-of-concept, giving security researchers a clearer look at how a specially crafted PDF can crash vulnerable iPhones and Macs.
Tracked as CVE-2026-86950, the flaw affects Apple’s CoreGraphics framework, which handles tasks including 2D graphics rendering and PDF processing. Apple said the vulnerability may have been used in an extremely sophisticated attack targeting specific individuals on older versions of iOS.
The proof-of-concept was published on September 30 by researchers Dion Blazakis, Josh Maine, and Anna Groza from security firm Calif. Their analysis began with a binary comparison between iOS 26.7 and iOS 26.7.1, the version that introduced Apple’s fix.
Researchers found that CoreGraphics was the only library changed in the update, with similar fixes applied across more than 20 locations in eight rasterizer functions. The vulnerable code converts glyph coordinates from floating-point values into 32-bit fixed-point numbers.
Before the fix, two of those functions handled unusually large values differently. One saturated the value while the other truncated it. This difference could produce an incorrect bounding box for a font glyph, causing CoreGraphics to allocate a buffer that was smaller than the area it attempted to draw.
The researchers created a specially crafted TrueType font containing oversized coordinates to trigger the problem. They then embedded the font inside a malicious PDF and used text transformations and nested composite-glyph scaling to push the values beyond their expected limits.
When the PDF is processed, the flaw can result in a controlled out-of-bounds write. Calif said the resulting crash affects both macOS and iOS, although the published macOS analysis includes a complete debugger stack while the iOS finding is based on the researchers’ testing.
The researchers emphasized that the proof-of-concept demonstrates a crash and a memory-corruption primitive, not a complete exploit capable of executing arbitrary code. Turning the memory corruption into reliable code execution would require additional exploitation work.
Apple released its security update for the vulnerability on September 28 and credited Meta Product Security with discovering the issue. The company said the flaw may have been used in targeted attacks against users running versions of iOS before iOS 27.
The U.S. Cybersecurity and Infrastructure Security Agency subsequently added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog and gave federal agencies until October 2 to apply the available security update.
Calif also investigated whether WhatsApp could have played a role in delivering the malicious PDF because Meta Product Security was credited with finding the Apple vulnerability.
The researchers compared WhatsApp versions 26.37.73 and 26.38.74 and found changes to the app’s Kaleidoscope attachment-scanning system. The newer version checks PDF files for embedded font streams and looks for several suspicious conditions, including malformed, undecodable, or unverified font programs.
Those changes provide circumstantial evidence that WhatsApp may have been considered as a possible delivery route, but Calif did not publish a tested WhatsApp exploitation path. The researchers initially suggested that a malicious PDF might be delivered through WhatsApp with limited user interaction, but that claim was later removed from the published analysis.
Meta has not publicly linked WhatsApp to the attacks involving CVE-2026-86950. The company also did not respond to questions about whether the messaging platform was involved before publication.
Calif said it did not obtain the actual exploit sample used in the attacks and therefore cannot determine how the attackers turned the CoreGraphics memory corruption into a complete attack chain.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
For users, the main protection remains installing Apple’s security updates as soon as possible. No workaround has been provided for devices that cannot immediately update, and Apple has not publicly confirmed whether Lockdown Mode would have prevented the reported attack path.



