Full Report
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working
Analysis Summary
# Vulnerability: Apple CoreGraphics Out-of-Bounds Write via Malicious PDF Fonts
## CVE Details
- **CVE ID:** CVE-2026-86950
- **CVSS Score:** Not explicitly listed in the article (High Severity inferred due to CISA KEV inclusion and "Targeted Attacks" designation).
- **CWE:** CWE-787 (Out-of-bounds Write) / CWE-122 (Heap-based Buffer Overflow)
## Affected Systems
- **Products:** iOS, iPadOS, macOS, and potentially applications using Apple's CoreGraphics framework for rendering (e.g., WhatsApp).
- **Versions:**
- iOS versions prior to 26.7.1 (specifically noted as used against individuals on versions before iOS 27).
- macOS versions prior to the September 28, 2026, patches.
- **Configurations:** Systems processing PDFs with embedded TrueType fonts, particularly through automated preview/thumbnail generation (ImageIO path).
## Vulnerability Description
The flaw resides in **CoreGraphics**, Apple’s framework for 2D drawing and PDF processing. The vulnerability stems from an inconsistency in how different rasterizer functions handle floating-point to 32-bit fixed-point conversions for glyph coordinates.
While some functions "saturated" out-of-range values, others "truncated" them. This discrepancy leads to the calculation of an incorrectly narrow bounding box for a glyph. Consequently, CoreGraphics allocates a memory buffer smaller than required. When the system attempts to draw the glyph, it performs an **out-of-bounds write** to the stack or heap, affecting two adjacent 16-bit values.
## Exploitation
- **Status:** **Exploited in the wild.** A public **PoC is available** (published by Calif researchers).
- **Complexity:** Medium (Achieving a crash is Low; turning the memory corruption into stable Remote Code Execution is High).
- **Attack Vector:** Local/Network (Delivered via malicious PDF; can be triggered via "zero-click" vectors like message attachment previews).
## Impact
- **Confidentiality:** High (Potential for full system compromise if chained with other flaws).
- **Integrity:** High (Potential for memory corruption and unauthorized code execution).
- **Availability:** High (Triggers immediate application or system crash).
## Remediation
### Patches
- **iOS / iPadOS 26.7.1:** Released September 28, 2026.
- **macOS:** Corresponding security updates released September 28, 2026.
- **WhatsApp:** Version 26.38.74 (includes updated attachment scanning to flag suspicious font programs).
### Workarounds
- There are no official workarounds described for systems that cannot update.
- Users are advised to disable "Automatic Media Downloads" in messaging apps like WhatsApp to mitigate zero-click triggers.
## Detection
- **Indicators of Compromise:**
- Frequent crashes of the CoreGraphics framework or ImageIO during PDF thumbnailing.
- PDFs containing TrueType fonts with extremely large coordinate values or nested composite-glyph scaling.
- **Detection Methods:**
- CISA has added this to the Known Exploited Vulnerabilities (KEV) catalog.
- WhatsApp has implemented internal scanners for `MalformedFontProgram`, `UndecodableFontProgram`, and `UnverifiedFontProgram` tags.
## References
- **Vendor Advisory:** Apple Security Updates (Sept 28, 2026)
- **CISA KEV Catalog:** [https://www.cisa.gov/known-exploited-vulnerabilities-catalog]
- **Researcher PoC:** [https://github[.]com/califio/publications/tree/main/MADBugs/CVE-2026-86950]
- **Technical Analysis:** [https://calif[.]io/research/the-great-glyph-grift]