INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Apple CoreGraphics Zero-Day Exploit Released with Public Proof of Concept
| 2026-10-01 12:08 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A highly sophisticated attack exploiting a zero-day vulnerability in Apple's CoreGraphics has been reported, with the first public proof-of-concept (PoC) released for CVE-2026-86950. The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and Sequoia. Apple has patched the issue with software updates, including iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. However, researchers have warned that attackers can trigger the flaw by tricking victims into opening malicious files sent through various channels, highlighting a potential risk to targeted individuals running older versions of iOS before iOS 27.
Technical Mitigations AI-generated
• Implement improved bounds checking to prevent out-of-bounds writes in CoreGraphics.
• Validate and sanitize user-input files before processing them, especially for images and PDFs.
• Regularly update operating systems (iOS, iPadOS, macOS) with the latest security patches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86950CVE-2026-86950
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
August 2025
Threat actors used a combination of vulnerabilities in WhatsApp's linked-device synchronization and an Apple CoreGraphics zero-day, CVE-2026-86950, to target fewer than 200 users.
Click on any entity below to view its context and source!
organisation
THN
In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities
THN covered at the time
.
victims
200 targeted users
In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities
THN covered at the time
.
September 28
Threat actors used the publicly disclosed Apple CoreGraphics zero-day CVE-2026-86950 to target specific individuals on versions of iOS before iOS 27.
Click on any entity below to view its context and source!
infrastructure
Ios
Apple patched the flaw on
September 28
, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
general_metric
27 iOS
Apple patched the flaw on
September 28
, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
organisation
Meta Product Security
Apple patched the flaw on
September 28
, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
infrastructure
Macos
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
September 30
Researchers Dion Blazakis, Josh Maine, and Anna Groza of Calif published an analysis on September 30 detailing their findings about a zero-day vulnerability in Apple CoreGraphics.
Click on any entity below to view its context and source!
organisation
Dion Blazakis
What the Researchers Found
The analysis was published September 30 by Dion Blazakis, Josh Maine, and Anna Groza of
Calif
, a firm known for research into
zero-click attack surfaces
in messaging apps.
2026/10/01
Researchers at Calif published a proof-of-concept that triggers the Apple CoreGraphics zero-day CVE-2026-86950 on macOS and iOS.
Click on any entity below to view its context and source!
organisation
Apple CoreGraphics Zero-Day CVE-2026-86950
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950.
organisation
PoC Released
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks.
organisation
Apple
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks.
Security researchers have published the first public proof-of-concept for
CVE-2026-86950
, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.
organisation
CoreGraphics
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks.
CoreGraphics is the Apple framework for 2D drawing, image rendering, and PDF processing.
organisation
Apple CoreGraphics
“Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.”
Security researchers have published the first public proof-of-concept for
CVE-2026-86950
, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.
infrastructure
Ios
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
Apple says it knows of a report that the flaw may have been exploited in an “extremely sophisticated attack against specific targeted individuals” running versions of iOS before iOS 27.
Researchers at Calif
published
a PoC that triggers the bug on macOS and iOS.
They started from a publicly available binary comparison of iOS 26.7 and 26.7.1.
The researchers say the crash occurs on both macOS and iOS.
The iOS claim is Calif's, with no separate trace published.
infrastructure
Macos
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
Researchers at Calif
published
a PoC that triggers the bug on macOS and iOS.
The researchers say the crash occurs on both macOS and iOS.
The macOS result includes a full debugger call stack.
infrastructure
26.7
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
organisation
macOS Tahoe
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
infrastructure
26.7.1
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
infrastructure
15.8.1
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
organisation
Meta Product Security
Meta Product Security discovered and reported the vulnerability to Apple.
organisation
Meta
The involvement of Meta is particularly interesting because the company has previously identified attacks involving Apple vulnerabilities and targeted users of its messaging platforms.
The Hacker News asked Meta whether WhatsApp was involved in the reported attacks.
organisation
The Hacker News
The Hacker News asked Meta whether WhatsApp was involved in the reported attacks.
organisation
WhatsApp
They noticed Meta credited the finding, so they compared two recent WhatsApp builds and found Meta had quietly added stricter PDF validation to WhatsApp’s attachment-scoring system, including new checks that flag malformed or unverifiable embedded fonts.
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path.
organisation
PDF
They noticed Meta credited the finding, so they compared two recent WhatsApp builds and found Meta had quietly added stricter PDF validation to WhatsApp’s attachment-scoring system, including new checks that flag malformed or unverifiable embedded fonts.
The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs.
organisation
Apple CoreGraphics PoC Emerges
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path.
organisation
iPhones
The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs.
“The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs.
organisation
Macs
The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs.
“The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs.
organisation
TrueType
“We’ve provided our minimal PDF and TrueType font generation scripts, a sample harness, and a Makefile for generating this example crashing file in our
GitHub repository
.”
To trigger the bug, the researchers built a TrueType font with coordinates large enough to force the overflow.
organisation
PoC
That’s not a small gap, but it’s also not nothing, since a crash PoC against a zero-click surface is exactly the kind of thing defenders want to study before attackers get there first.
CoreGraphics’ rasterizer is used everywhere fonts get drawn on Apple platforms, which means the attack surface isn’t limited to one app.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Apple)
infrastructure
26.37.73
The firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp's
Kaleidoscope
attachment scanner.
infrastructure
26.38.74
The firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp's
Kaleidoscope
attachment scanner.
organisation
The WhatsApp Question
The WhatsApp Question
Calif examined WhatsApp because Meta Product Security was credited with finding the flaw.
October 2
The U.S. Cybersecurity and Infrastructure Security Agency added the Apple CoreGraphics zero-day vulnerability CVE-2026-86950 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply the fix by October 2.
Click on any entity below to view its context and source!
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency
added the flaw
to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency
added the flaw
to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.
Tactical Metrics
Metrics
infrastructure
Ios
Affected Product
Click for context!
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
Apple says it knows of a report that the flaw may have been exploited in an “extremely sophisticated attack against specific targeted individuals” running versions of iOS before iOS 27.
Researchers at Calif
published
a PoC that triggers the bug on macOS and iOS.
Apple patched the flaw on
September 28
, crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
They started from a publicly available binary comparison of iOS 26.7 and 26.7.1.
The researchers say the crash occurs on both macOS and iOS.
The iOS claim is Calif's, with no separate trace published.
Metrics
infrastructure
Macos
Affected Product
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
Researchers at Calif
published
a PoC that triggers the bug on macOS and iOS.
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
The researchers say the crash occurs on both macOS and iOS.
The macOS result includes a full debugger call stack.
Metrics
infrastructure
26.7
Software Version
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia.
Metrics
infrastructure
26.7.1
Software Version
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
Metrics
infrastructure
15.8.1
Software Version
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
Metrics
infrastructure
26.37.73
Software Version
The firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp's
Kaleidoscope
attachment scanner.
Metrics
infrastructure
26.38.74
Software Version
The firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp's
Kaleidoscope
attachment scanner.
Metrics
victims
200
Targeted Users
In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities
THN covered at the time
.
Intelligence Sources
The Hacker News
2026-10-01
Security Affairs
2026-10-01
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:43
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
Apple CoreGraphics Zero-Day CVE-2026-86950
entity
6x
timeline
Temporal Reference
26.7
date
5x
infrastructure
Software Version
26.7
version
3x
general metric
Bit
32
bit
2x
infrastructure
Affected Product
Ios
software
2x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
Contextual Telemetry
Context Block
10 METRICS
vulnerability
Exploited CVE
CVE-2026-86950
cve
general metric
Cve-2026
86,950
cve-2026
general metric
Versions
27
versions
general metric
Ios
27
ios
general metric
Grid
4,096
grid
industry
Targeted Sector
Media
sector
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
victims
Targeted Users
200
targeted users
general metric
Times
20
times
general metric
Minutes
85
minutes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.