← Back to Daily Briefing (#TargetedAttack)

Apple CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks

Published October 2, 2026

In late September 2026 Apple disclosed CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework triggered by a malicious PDF containing a crafted embedded font, enabling arbitrary code execution on unpatched iOS (<27) and macOS (Ventura <13.6, Monterey <12.7, Big Sur <11.7). The flaw was actively exploited in highly targeted attacks against high-value individuals. Emergency updates were released; public PoC appeared shortly after. Impact includes full device compromise, data exfiltration, and persistence.

  • Overview
  • Disclosed Sep 29 2026 via Apple Security Advisory 2026-09-29.
  • Affects iOS/iPadOS <27, macOS Ventura <13.6, Monterey <12.7, Big Sur <11.7.
  • Patched in iOS 27.x, macOS Ventura 13.6+, Monterey 12.7+, Big Sur 11.7+.

  • Vulnerability Mechanics

  • Triggered when CoreGraphics parses an embedded font table in a PDF.
  • Out-of-bounds write corrupts memory, allowing arbitrary code execution.
  • Exploitation requires only opening or previewing the malicious PDF; no extra privileges.
  • Public PoC demonstrates font heap spray and ROP chain to achieve code execution.

  • Impact & Exploitation Status

  • CVSS v3.1 score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/H:A).
  • Observed attacks against executives, journalists, and government officials.
  • Consequences: full device compromise, data exfiltration, persistence.
  • Activity remains highly targeted; no widespread worm-like spread observed.

  • Detection & Mitigation

  • Apply Apple emergency updates; verify OS build numbers.
  • Enable Lockdown Mode for high‑risk users.
  • Block untrusted PDFs at email gateways or via endpoint protection.
  • Monitor for anomalous CoreGraphics crashes or unexpected process spawns.

  • Conclusion

  • Highlights persistent risk of font‑based attacks in Apple’s graphics stack.
  • Reinforces need for rapid zero‑day patch management and user awareness.
  • CISOs should prioritize asset inventory and enforce least‑privilege PDF handling.

Related posts

  1. Cybersecurity News — Critical Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks
  2. News4Hackers — Apple Patches Zero-Day Exploit in Sophisticated Attack (CVE-2026-86950)
  3. www.helpnetsecurity.com — Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
  4. bleepingcomputer.com — Apple patches CoreGraphics zero-day flaw exploited in attacks
  5. socprime.com — CVE-2026-86950: Apple CoreGraphics Zero-Day Linked to Extremely Sophisticated Targeted Attacks
  6. The Hacker News — Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
  7. Security Affairs — Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
  8. Nvd
  9. Tenable
  10. Bitdefender
  11. Techrepublic
  12. Bgr
  13. Calif
  14. Infosecurity-magazine
  15. Rodtrent

LINK COPIED TO CLIPBOARD