Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.

Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.
Apple patched the flaw on September 28 , crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." The U.S.
Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.
In February 2025, for example, researchers at The Citizen Lab found CVE-2025-24200, which Apple said had been exploited “in an extremely sophisticated attack against specific targeted individual.” Apple this month also patched CVE-2026-86869, a critical zero-click vulnerability which could have been silently triggered via a maliciously crafted iMessage.
The initial version did: it said the researchers' analysis suggested WhatsApp could deliver a PDF that triggers the flaw when a victim opens a chat from a trusted contact with automatic media downloads on.
In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities THN covered at the time .
New AmnesiaStealer macOS malware hijacks browser sessions via remote control Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
The other one, an arbitrary code execution vulnerability in dyld (the Dynamic Link Editor used by Apple operating systems) tracked as CVE-2026-20700 and also exploited in extremely sophisticated targeted attacks, was patched in February .
Last year, Apple fixed seven more zero-days exploited in the wild, the first in January (CVE-2025-24085), the second in February (CVE-2025-24200), a third in March (CVE-2025-24201), two more in April (CVE-2025-31200 and CVE-2025-31201), and two others in December (CVE-2025-43529 and CVE-2025-14174).
What happened
Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.
Apple patched the flaw on September 28 , crediting Meta Product Security with the discovery and noting it may have been used in an "extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." The U.S.
What changed
Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.
In February 2025, for example, researchers at The Citizen Lab found CVE-2025-24200, which Apple said had been exploited “in an extremely sophisticated attack against specific targeted individual.” Apple this month also patched CVE-2026-86869, a critical zero-click vulnerability which could have been silently triggered via a maliciously crafted iMessage.
Who is affected
The initial version did: it said the researchers' analysis suggested WhatsApp could deliver a PDF that triggers the flaw when a victim opens a chat from a trusted contact with automatic media downloads on.
In August 2025, WhatsApp assessed that a flaw in its linked-device synchronization messages may have been combined with a separate Apple out-of-bounds write and used against fewer than 200 targeted users, a pair of vulnerabilities THN covered at the time .
Why it matters
New AmnesiaStealer macOS malware hijacks browser sessions via remote control Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.
Technical details
The other one, an arbitrary code execution vulnerability in dyld (the Dynamic Link Editor used by Apple operating systems) tracked as CVE-2026-20700 and also exploited in extremely sophisticated targeted attacks, was patched in February .
Last year, Apple fixed seven more zero-days exploited in the wild, the first in January (CVE-2025-24085), the second in February (CVE-2025-24200), a third in March (CVE-2025-24201), two more in April (CVE-2025-31200 and CVE-2025-31201), and two others in December (CVE-2025-43529 and CVE-2025-14174).
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
Response
Apple has not said whether Lockdown Mode would have blocked the delivery path used in the reported attacks.
There was no further information from Apple on CVE-2026-86950 except that it has been fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
What security teams should do
While this flaw is likely exploited only in highly targeted attacks, it is strongly advised to install these security updates promptly to prevent potential ongoing attacks.
No workaround has been described for systems that cannot update immediately.
What remains unknown
Apple has not said whether Lockdown Mode would have blocked the delivery path used in the reported attacks.
Attribution
The Hacker News: Security researchers have published the first public proof-of-concept for CVE-2026-86950 , an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.
Infosecurity Magazine: In a bulletin on September 28, the tech giant attributed the discovery of CVE-2026-86950 to the Meta Product Security team.
BleepingComputer: Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.