Apple CoreGraphics Zero-Day CVE-2026-86950 Exploited in Targeted Attacks
In late September 2026 Apple disclosed CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework triggered by a malicious PDF containing a crafted embedded font, enabling arbitrary code execution on unpatched iOS (<27) and macOS (Ventura <13.6, Monterey <12.7, Big Sur <11.7). The flaw was actively exploited in highly targeted attacks against high-value individuals. Emergency updates were released; public PoC appeared shortly after. Impact includes full device compromise, data exfiltration, and persistence.
- Overview
- Disclosed Sep 29 2026 via Apple Security Advisory 2026-09-29.
- Affects iOS/iPadOS <27, macOS Ventura <13.6, Monterey <12.7, Big Sur <11.7.
-
Patched in iOS 27.x, macOS Ventura 13.6+, Monterey 12.7+, Big Sur 11.7+.
-
Vulnerability Mechanics
- Triggered when CoreGraphics parses an embedded font table in a PDF.
- Out-of-bounds write corrupts memory, allowing arbitrary code execution.
- Exploitation requires only opening or previewing the malicious PDF; no extra privileges.
-
Public PoC demonstrates font heap spray and ROP chain to achieve code execution.
-
Impact & Exploitation Status
- CVSS v3.1 score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/H:A).
- Observed attacks against executives, journalists, and government officials.
- Consequences: full device compromise, data exfiltration, persistence.
-
Activity remains highly targeted; no widespread worm-like spread observed.
-
Detection & Mitigation
- Apply Apple emergency updates; verify OS build numbers.
- Enable Lockdown Mode for high‑risk users.
- Block untrusted PDFs at email gateways or via endpoint protection.
-
Monitor for anomalous CoreGraphics crashes or unexpected process spawns.
-
Conclusion
- Highlights persistent risk of font‑based attacks in Apple’s graphics stack.
- Reinforces need for rapid zero‑day patch management and user awareness.
- CISOs should prioritize asset inventory and enforce least‑privilege PDF handling.
Related posts
- Cybersecurity News — Critical Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks
- News4Hackers — Apple Patches Zero-Day Exploit in Sophisticated Attack (CVE-2026-86950)
- www.helpnetsecurity.com — Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
- bleepingcomputer.com — Apple patches CoreGraphics zero-day flaw exploited in attacks
- socprime.com — CVE-2026-86950: Apple CoreGraphics Zero-Day Linked to Extremely Sophisticated Targeted Attacks
- The Hacker News — Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- Security Affairs — Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
- Nvd
- Tenable
- Bitdefender
- Techrepublic
- Bgr
- Calif
- Infosecurity-magazine
- Rodtrent