
Proof-of-Concept Reveals How Malicious PDFs Trigger Apple CoreGraphics Crash
Security researchers have released a proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw patched on September 28. The vulnerability, triggered by a malicious PDF with a crafted font, causes a crash on unpatched iOS and macOS devices. While Apple confirmed the flaw was used in targeted attacks, the new analysis demonstrates only a memory corruption crash, not full code execution. CISA mandated federal agencies patch by October 2, and researchers noted potential links to WhatsApp delivery mechanisms, though Meta has not confirmed involvement.













