CVE-2026-86950: Apple CoreGraphics Zero-Day Exploited in Targeted Spyware Attacks

Apple CoreGraphics CVE-2026-86950 Exploit Analysis
📌
Security Roundup Series: Week of October 2, 2026 • 4 min read deep dive
🚨
Vulnerability Intelligence: CVE ID: CVE-2026-86950 (CWE-787 (Out-of-Bounds Write)) Severity: HIGH / CRITICAL (CVSS 8.8) Status: Actively Exploited Zero-Day (CISA KEV Deadline Oct 2, 2026) Affected Systems: iOS versions prior to 26.7.1, iPadOS prior to 26.7.1, macOS Sequoia prior to 15.8.1, macOS Tahoe prior to 26.7.1 Fixed In: iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1

On September 28, 2026, Apple issued rapid security patches across iOS, iPadOS, and macOS to remediate CVE-2026-86950, an out-of-bounds write flaw in the CoreGraphics framework. Threat intelligence confirms that advanced commercial spyware brokers actively weaponized this flaw in targeted, zero-click mobile campaigns against civil society figures, journalists, and enterprise executives. CISA mandated that federal agencies complete patching and forensic analysis by October 2, 2026.

Root Cause: Coordinate Conversion Math in Vector Rasterization

The vulnerability exists within the vector path rasterization engine inside CoreGraphics.framework. When parsing complex glyph paths in embedded PDF streams or custom font descriptors, the engine converts user-specified 64-bit floating-point coordinates into fixed-point representations (e.g., 24.8 or 16.16 format) for raster scanning:

/* Simplified vulnerability logic in path rasterization */
void rasterize_bezier_segment(double x1, double y1, double x2, double y2, uint8_t *pixel_buf, size_t buf_size) {
    // FLAW: Converting extreme floating-point coordinates causes 32-bit integer overflow
    int32_t fixed_x = (int32_t)(x1 * 256.0);
    int32_t fixed_y = (int32_t)(y1 * 256.0);
    
    // Bounds calculation based on overflowed integer calculates negative or truncated memory offsets
    size_t offset = (fixed_y * stride) + fixed_x;
    
    // Unchecked memory write corrupts adjacent heap metadata
    pixel_buf[offset] = 0xFF;
}

By supplying pathological Bézier curve control points exceeding normal coordinate boundaries, an attacker triggers integer overflow during fixed-point scaling. The resulting memory index wraps around, directing rasterized pixel bytes into adjacent heap chunks. In weaponized exploit chains, this out-of-bounds write corrupts objective-C object pointers, hijacking control flow and escaping the BlastDoor sandbox.

Attack Vector & Delivery Method

Zero-Click Delivery (iMessage / APNs / Mail Attachment)
  │
  ├──► [Attachment Download] -> PDF / Custom Font Attachment
  │
  ├──► [BlastDoor & ImageIO Sandbox]
  │      │
  │      ├──► CoreGraphics Path Rasterizer
  │      │      └── Pathological Floating-to-Fixed Point Conversion
  │      │
  │      ▼
  ├──► [Heap Corruption] -> Out-of-Bounds Write (CWE-787)
  │      │
  │      ▼
  └──► [Arbitrary Code Execution] -> Memory disclosure & privilege escalation

Defensive Telemetry & Action Items

  1. Immediate Operating System Updates: Push mandatory configuration profiles enforcing updates to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 across all managed Apple devices.
  2. Enable Lockdown Mode for High-Risk Personnel: For executives, legal counsel, and employees handling sensitive data, enforce Apple Lockdown Mode, which disables complex font rendering and remote attachment pre-processing.
  3. Unified Endpoint Management (UEM) Compliance: Quarantine mobile devices that fail to report the patched build version following the October 2 deadline.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther