Proof-of-Concept Exploit Published for Apple PDF Flaw Linked to Targeted Attacks
Security researchers have published the first public proof-of-concept for CVE-2026-86950, a flaw in Apple's CoreGraphics framework, which handles 2D drawing and PDF processing on iPhones and Macs. The issue is triggered by a malicious PDF containing a specially crafted font, which can crash unpatched devices. Researchers note that this crash does not amount to full remote code execution on its own, but it demonstrates a real and reproducible weakness in how Apple devices process certain PDF attachments, including when previewing files in messaging apps.
Apple patched the flaw on September 28, crediting Meta's security team with discovering it, and stated it may have been used in a highly sophisticated attack against specific targeted individuals running versions of iOS prior to iOS 27. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog the next day, ordering federal agencies to patch by October 2. Apple has not listed iOS 27 or macOS Golden Gate 27 as affected, and no workaround exists for devices that cannot be updated right away.
The research, published by a team at Calif, a firm specialising in messaging app security, traced the fix to more than twenty code changes across Apple's image rendering functions. While this appears to have been used in narrow, targeted attacks rather than mass campaigns, public proof-of-concept code increases the risk that broader exploitation attempts could follow.