high Cve 2026 86950 · Exploits

Apple Patches CoreGraphics Zero-Day Used Against Targeted iPhone Users

Data graphic: Apple's CoreGraphics zero-day CVE-2026-86950 , an out-of-bounds write that lets a crafted file run code on iPhone, iPad and Mac, scores CVSS 3.1 8.8 and is exploited per CISA KEV. Fixes are iOS, iPadOS and macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, with a CISA KEV deadline of 2 Oct.
AK

Threat intelligence editor · Updated Oct 2, 2026, 8:06 AM EDT

CVE-2026-86950, a CoreGraphics out-of-bounds write hit via a crafted file, was exploited on iOS before 27. Update to iOS 26.7.1, macOS 26.7.1 or 15.8.1.

Apple has patched a CoreGraphics zero-day that it says may have been used in "an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." The flaw, CVE-2026-86950, is an out-of-bounds write that turns a maliciously crafted file into arbitrary code execution. The fixes shipped on 28 September 2026 in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. The people most exposed are those who stayed on iOS 26 instead of moving to iOS 27, which is exactly the version range Apple's exploitation note describes.

Meta Product Security reported the bug. CISA added it to the Known Exploited Vulnerabilities catalog on 29 September, with a remediation deadline of 2 October 2026 for federal civilian agencies. On 1 October, researchers at Calif published a root-cause write-up and a proof-of-concept that crashes CoreGraphics. Their PoC stops at the crash and does not reach code execution, but the path from a file to the memory corruption is now public.


Who is affected

Apple's three advisories list the same single CVE, all released on 28 September:

PlatformVulnerableFixed in
iOS and iPadOSbefore 26.7.126.7.1
macOS Tahoe26.0 up to 26.7.126.7.1
macOS Sequoiabefore 15.8.115.8.1

The iOS and iPadOS update covers iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later).

NVD's record lists no affected iOS 27 or macOS 27 versions, and Apple's exploitation note is limited to iOS versions before iOS 27. Devices already on the 27 branch are not in the affected ranges. Devices held back on iOS 26, whether by choice, by an MDM deferral policy or by app compatibility testing, are the ones that need 26.7.1 now.

Data graphic: timeline of CVE-2026-86950. Apple patches on 28 Sep, CISA adds it to KEV on 29 Sep, Calif publishes a crash PoC on 1 Oct, and the KEV remediation deadline falls on 2 Oct, four days after the patch.

From Apple's fix to the federal KEV deadline took four days, and a public crash PoC arrived a day before it. Sources: Apple, CISA, Calif.


How the bug works

CoreGraphics is the 2D drawing engine under text, PDF and image rendering on Apple platforms. Calif found the fix by diffing the CoreGraphics framework between iOS 26.7 and 26.7.1. The patch touched more than 20 identical code patterns across eight aa_* functions in the anti-aliased path rasterizer, the code that smooths the edges of glyphs and other shapes.

The root cause is a unit conversion in an inline helper, aa_double_to_fixed(), which multiplies floating-point coordinates by 4096 to turn them into fixed-point integers. When the double is too large for a 32-bit integer, the conversion is undefined behaviour in C, and the compiler emitted different instructions in different places:

  • aa_moveto used the ARM64 FCVTZS instruction, which saturates to INT32_MAX.
  • aa_lineto converted to a 64-bit value and then truncated it to 32 bits.

The two functions therefore disagreed about where the same oversized coordinate was. The bounding box computed in aa_add_edges() came out smaller than the edges actually drawn, the coverage buffer was allocated too small, and rendering wrote past its end.

To reach it, Calif built a PDF with a crafted TrueType font, combining the PDF text matrix with nested composite-glyph scaling transforms to push glyph coordinates past the 32-bit range. Apple describes its fix as improved bounds checking.

Data graphic: how CVE-2026-86950 works. A crafted PDF font causes a coordinate overflow; one function saturates and another truncates the value, so the bounding box comes out too small and rendering writes past the buffer. Apple patched 20+ code patterns in 8 rasterizer functions; the fixed-point scale is x 4096 and the integer width 32-bit.

The two rasterizer functions disagree about the same oversized coordinate, so the coverage buffer is allocated too small. Source: Calif root-cause write-up.


What we know about the attacks

Apple has not said who was targeted, how many people, or how the file was delivered. The advisory names no actor and no victim count.

Calif points to one clue. Meta, which reported the bug, has since added strict PDF validation and FontFile parsing to WhatsApp, which suggests the exploit arrived as a PDF attachment. That is the researchers' inference, not a statement from Apple or Meta.


What to do

  1. Update now. Install iOS or iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, or move to the 27 releases. On iPhone and iPad: Settings, General, Software Update.
  2. Check your MDM deferrals. Fleets that deliberately hold devices on iOS 26 should push 26.7.1 as a security-only update without waiting for the 27 rollout.
  3. Federal agencies were due to remediate under the KEV listing by 2 October 2026.
  4. High-risk users, such as journalists, activists and officials, should consider turning on Apple's Lockdown Mode, as Bitdefender recommends for people likely to be singled out.
  5. Treat unexpected PDFs as hostile, especially ones arriving through messaging apps. A file that looks normal can still carry a crafted embedded font.

Sources

Keep reading

All latest →
  1. criticalExploitsCheck Point Management Servers Were a Zero-Day for Two Months Before the Fix6 min
  2. criticalExploitsCisco SD-WAN Manager Zero-Day CVE-2026-76504: One Encoded Character Unlocks the Admin API5 min
  3. criticalExploitsExploited FortiMail Flaw Has No Patch Yet: Disable IBE Now5 min
  4. criticalExploitsCitrix NetScaler Zero-Days Planted Webshells Weeks Before the Patch8 min
  5. criticalExploitsUnder Active Attack: Cisco ISE Zero-Day (CVE-2026-76460) Grants Remote Unauthenticated Admin Access8 min
  6. criticalExploitsShieldCrash Zero-Day Analysis: Bypassing Microsoft Defender's ShieldBreak Fix (CVE-2026-69414) for Arbitrary SYSTEM File Reads7 min