National Cyber Warfare Foundation (NCWF)

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950


0 user ratings
2026-10-01 12:32:04
milo
Blue Team (CND)
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […


Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available.





Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file.





The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.





“Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” reads Apple’s advisory. “Description: “An out-of-bounds write issue was addressed with improved bounds checking.”





The more important sentence, however, is the one that turns this from another vulnerability disclosure into a security incident worth watching. Apple says it knows of a report that the flaw may have been exploited in an “extremely sophisticated attack against specific targeted individuals” running versions of iOS before iOS 27.





Apple hasn’t disclosed who was targeted, how many people were affected, whether the attacks succeeded, or when exploitation started. It also hasn’t explained how attackers delivered the malicious files. That leaves an important part of the attack chain unknown.





CoreGraphics handles graphics and rendering functions across Apple’s operating systems, including processing content such as images and PDFs. Attackers can trigger the flaw by tricking the victim into opening a malicious file sent through a web page, an email attachment, or a messaging application, However, Apple hasn’t confirmed any of these delivery methods for CVE-2026-86950.





That distinction matters. A crafted file doesn’t need to look like an obvious executable for a vulnerability in a system component that processes content to become useful to an attacker. The security boundary can be crossed while the operating system is simply doing what it’s designed to do: interpreting a file.





Meta Product Security discovered and reported the vulnerability to Apple. The involvement of Meta is particularly interesting because the company has previously identified attacks involving Apple vulnerabilities and targeted users of its messaging platforms.





Apple did not provide many details, which is common with security fixes. Researchers at Calif analyzed the patch and published a detailed report called The Great Glyph Grift. It explains how a small rounding error in font rendering could eventually lead to memory corruption on Apple devices.





The bug was in CoreGraphics, specifically in the code that smooths the edges of letters and other shapes. CoreGraphics converts floating-point coordinates into a fixed-point format, dividing each pixel into a 4096 × 4096 grid of smaller units.





The problem happened when a number was too large to fit into a 32-bit integer. Different parts of CoreGraphics handled this overflow differently. One function limited the value to the maximum allowed integer, while another simply truncated it. This mismatch created the vulnerability.





“Converting between a double and an int32_t, when the double value exceeds the bounds of an int32_t (i.e., outside the range of [-2147483648, 2147483647]), is undefined behavior and clang may optimize this to use different floating point conversion instructions. Before the patch, aa_moveto used the ARM64 instruction FCVTZS Wd, Dn to convert to a 32-bit integer, saturating to INT32_MAX or INT32_MIN on overflow.” reads the Calif’s report. “The other function, aa_lineto, converted the double to 64-bit integers with the ARM64 instruction FCVTZS Vd.2D,Vn.2D, then used XTN to keep the low 32 bits (truncation). The patch ensures the scaled value can never exceed the size of a 32-bit signed integer using manual clamping (as shown above) to avoid the undefined behaviour entirely.”





When a glyph’s path gets recorded, CoreGraphics builds a bounding box from all the edge coordinates to figure out how big a buffer it needs for rendering. If one coordinate wraps around due to the truncation bug, the subtraction used to compare points can flip sign, and the bounding box calculation picks the wrong edge. The box ends up smaller than it should be.





That undersized box feeds straight into an allocation decision. Small buffer, real edges, the renderer writes past the end of it. Classic out-of-bounds write, just reached through a genuinely weird path involving font math instead of the usual string parsing.





Calif didn’t stop at the CoreGraphics patch. They noticed Meta credited the finding, so they compared two recent WhatsApp builds and found Meta had quietly added stricter PDF validation to WhatsApp’s attachment-scoring system, including new checks that flag malformed or unverifiable embedded fonts. That’s a strong hint about the delivery format: a booby-trapped font inside a PDF, sent as an attachment.





Worth noting, the researchers were upfront about the limits of their own work.





“We’ve provided our minimal PDF and TrueType font generation scripts, a sample harness, and a Makefile for generating this example crashing file in our GitHub repository.” the report continues. “Going from this to code execution is another exercise entirely.”





They built a reliable crash, not a working exploit chain. That’s not a small gap, but it’s also not nothing, since a crash PoC against a zero-click surface is exactly the kind of thing defenders want to study before attackers get there first.





CoreGraphics’ rasterizer is used everywhere fonts get drawn on Apple platforms, which means the attack surface isn’t limited to one app. Anywhere a file gets automatically rendered into a thumbnail or preview is a potential trigger, no user interaction required beyond receiving the file. That’s the whole appeal of zero-click bugs to attackers and the whole nightmare for defenders.





The Hacker News revealed that proof-of-concept (PoC) code is now circulating publicly, which raises the urgency for anyone who hasn’t patched yet.





“Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.” The Hacker News reports. “The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate.”





This isn’t a bug you can mitigate with better input sanitization on your own app, since the flaw sits inside the OS rendering stack itself. Updating is the fix, full stop. And if you’re the kind of team that reads vendor advisories literally, maybe start reading “sophisticated attack against specific targeted individuals” as the understatement it actually is.





Researchers at Calif published a PoC that triggers the bug on macOS and iOS.





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, Apple)







Source: SecurityAffairs
Source Link: https://securityaffairs.com/200175/hacking/public-poc-released-for-apple-coregraphics-zero-day-cve-2026-86950.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.