hacker-news · Crawled Oct 1, 2026

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

1 IoCs
Read original article ↗

AI Summary

Security researchers from Calif have published a proof-of-concept for CVE-2026-86950, a vulnerability in Apple's CoreGraphics framework that can be triggered by a malicious PDF containing a crafted embedded font, leading to a crash due to an out-of-bounds write. The flaw affects unpatched versions of iOS and macOS and was patched by Apple on September 28, 2026, after being reported by Meta Product Security. While no active exploit has been demonstrated, the vulnerability could serve as part of a zero-click attack chain, with circumstantial evidence suggesting WhatsApp as a potential delivery vector due to changes in its attachment scanning logic.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo Calif/public Details →