Apple CoreGraphics CVE-2026-86950: OOB write (targeted iOS); Calif PDF/font crash research 30 Sep; CISA KEV due 2 Oct
Apple security content for iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 (published 28 September 2026; The Hacker News amplified same day) patches CVE-2026-86950 in CoreGraphics: an out-of-bounds write addressed with improved bounds checking. Impact: processing a maliciously crafted file may lead to arbitrary code execution. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27 — no public detail on volume, success, or first-seen date. Credited to Meta Product Security. No Apple-published CVSS on the HT pages. Distinct from earlier February 2026 dyld CVE-2026-20700 (also noted as weaponised in sophisticated attacks). Primary: Apple HT149226 / HT149228 / HT149229; wire: The Hacker News 28–29 Sep. UPDATE 1 Oct 2026 (desk 16:00 Perth): Calif research “The Great Glyph Grift” (Dion Blazakis, Josh Maine, Anna Groza; 30 Sep) publishes patch-diff analysis and a public crash-trigger sample (TrueType/PDF via ImageIO thumbnail path) showing a controlled out-of-bounds write from glyph fixed-point conversion — crash demonstrated on macOS/iOS; authors state turning that into reliable code execution is separate work and they did not obtain the in-the-wild sample. Calif also notes WhatsApp Kaleidoscope (versions 26.37.73→26.38.74) added stricter PDF embedded-font checks, hinting a possible messaging attachment delivery path consistent with Meta Product Security credit — not confirmed as the in-the-wild vector. CISA added CVE-2026-86950 to the Known Exploited Vulnerabilities catalog on 29 Sep (due 2 Oct 2026). Wire: The Hacker News 1 Oct.
- Product
- Apple CoreGraphics (iOS / iPadOS / macOS)
- Versions
- Fixed: iOS 26.7.1 and iPadOS 26.7.1 (iPhone 11 and later; listed iPad models); macOS Tahoe 26.7.1; macOS Sequoia 15.8.1. Apple notes possible exploitation on iOS before iOS 27.
- Exploited in Australia?
- unknown
- Patch to
- Update to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1. CISA KEV due date 2 Oct 2026 for applicable US federal systems (BOD 26-04). Prefer updated WhatsApp; treat unsolicited PDFs/fonts as high risk on unpatched devices; prioritise high-risk users given Apple’s targeted-attack language.
Primary: Apple — About the security content of iOS 26.7.1 and iPadOS 26.7.1 (28 Sep 2026) · Vendor: Apple Product Security — CVE-2026-86950 CoreGraphics · CVE: CVE-2026-86950, CVE-2026-20700 · Calif — CVE-2026-86950 The Great Glyph Grift (30 Sep 2026); THN amplifies 1 Oct
