Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Your Driverless Cab Is Spying on You

    October 2, 2026

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    October 2, 2026

    Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Your Driverless Cab Is Spying on You
    • Microsoft’s X account hacked in crypto pump-and-dump scheme
    • Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network
    • California to Vote on Landmark Tribal Petitions for Coastal Protections
    • NBA closes sole Africa training academy in blow to young players | Basketball
    • First minister demands ‘new deal’ for Wales, before Plaid Cymru conference
    • Drumcree talks break up without agreement on fifth day of standoff | Northern Ireland
    • Health Care Workers Are Tired of Cleaning Up Palantir’s Mess
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 1, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.

    The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate.

    Apple patched the flaw on September 28, crediting Meta Product Security with the discovery and noting it may have been used in an “extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”

    The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.

    Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories. No workaround has been described for systems that cannot update immediately.

    What the Researchers Found

    The analysis was published September 30 by Dion Blazakis, Josh Maine, and Anna Groza of Calif, a firm known for research into zero-click attack surfaces in messaging apps. They started from a publicly available binary comparison of iOS 26.7 and 26.7.1.

    Cybersecurity

    CoreGraphics is the Apple framework for 2D drawing, image rendering, and PDF processing. It was the only library changed in 26.7.1, with the same fix applied more than 20 times across eight rasterizer functions.

    The patched code converts a glyph coordinate from floating-point to a 32-bit fixed-point value. Before the patch, two of the eight functions handled out-of-range values differently: one saturated the result, the other truncated it.

    That difference caused the calculated bounding box for a glyph to be too narrow. CoreGraphics then allocated a working buffer smaller than the edges it needed to draw, and wrote outside it.

    To trigger the bug, the researchers built a TrueType font with coordinates large enough to force the overflow. Embedding it in a PDF with a text matrix and nested composite-glyph scaling pushes those coordinates past the limit. They published the generation scripts and a sample PDF in a public GitHub repository.

    The harness calls the same ImageIO thumbnail path an app uses when previewing a received attachment. The researchers say the crash occurs on both macOS and iOS.

    The macOS result includes a full debugger call stack. The iOS claim is Calif’s, with no separate trace published.

    The crash exposes a controlled out-of-bounds write that affects two adjacent 16-bit values in a buffer that the attacker can control, allowing writes to the stack or heap. Calif says converting that primitive into working code execution is separate work. Calif did not obtain the in-the-wild sample and cannot say how the attacker completed the chain.

    The WhatsApp Question

    Calif examined WhatsApp because Meta Product Security was credited with finding the flaw. The firm compared two recent WhatsApp versions, 26.37.73 and 26.38.74, and found new code in WhatsApp’s Kaleidoscope attachment scanner.

    The newer version reads PDF files for embedded font streams and flags suspicious ones with three defect tags: MalformedFontProgram, UndecodableFontProgram, and UnverifiedFontProgram. Any such tag returns a high-risk score to WhatsApp’s attachment checker, which then stops automatic parsing of the flagged file.

    Calif described those changes as circumstantial evidence pointing toward WhatsApp as a possible delivery vector. The firm’s post describes its research as covering a possible WhatsApp zero-click path.

    The published analysis does not describe or test a WhatsApp delivery path. The initial version did: it said the researchers’ analysis suggested WhatsApp could deliver a PDF that triggers the flaw when a victim opens a chat from a trusted contact with automatic media downloads on.

    That sentence was removed 85 minutes after publication in a commit by Calif CEO Thai Duong, who described the change as removing the WhatsApp speculation.

    Cybersecurity

    The analysis closes with a question: whether the flaw “was combined with additional vulnerabilities in WhatsApp to reach parsing with less user interaction.” That phrasing suggests the path Calif studied would require user action or further WhatsApp vulnerabilities in the chain.

    WhatsApp has published no advisory linking this flaw to its products. Its 2026 advisory page lists two unrelated vulnerabilities.

    The Hacker News asked Meta whether WhatsApp was involved in the reported attacks. Meta did not respond before publication.

    An earlier case makes the hypothesis plausible. In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities THN covered at the time.

    The Hacker News asked Calif about the removed delivery claim and whether the researchers had obtained the in-the-wild sample since publication. Calif did not respond before publication.

    No network indicators, attacker identifiers, or exploit payload names have been made public. Apple has not said whether Lockdown Mode would have blocked the delivery path used in the reported attacks.

    Apple checks CoreGraphics Delivery emerges hint path PDF PoC WhatsApp
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Rolling the cyber dice with open-source and open-weight AI models

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Microsoft says threat actors are ahead in the early AI race

    Autonomous AI agents tried to hack US, Canadian government websites

    OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Your Driverless Cab Is Spying on You

    October 2, 2026

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    October 2, 2026

    Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network

    October 2, 2026

    California to Vote on Landmark Tribal Petitions for Coastal Protections

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Your Driverless Cab Is Spying on You

    October 2, 2026

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    October 2, 2026

    Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.