CVE-2026-86950: The CoreGraphics Glyph Bug That Hit iPhones

Researchers traced the exploited CoreGraphics flaw to a single unclamped floating-point conversion function, with a malicious PDF-embedded font as the likely WhatsApp delivery vector.

By Vivek • • 4 Min Read • 0 • Follow on Google News Add to Preferred Source
An in-the-wild iOS bug with a possible WhatsApp zero-click path.

Security firm Calif on Tuesday published a full technical breakdown of CVE-2026-86950, the CoreGraphics zero-day Apple silently patched in iOS 26.7.1, tracing the in-the-wild bug to an integer overflow in the font glyph rasterizer and identifying a credible WhatsApp-delivered PDF as the likely attack format.

Apple disclosed the flaw on September 29, crediting Meta Product Security and describing exploitation as “an extremely sophisticated attack against specific targeted individuals” — the company’s standard phrasing for confirmed in-the-wild use. The vulnerability carries a CVSS score of 8.8 and was added to the CISA Known Exploited Vulnerabilities catalog the same day. Cyber Kendra covered the initial patch, SlowMist’s link to crypto wallet attacks, and the list of affected devices when the advisory dropped. Dion Blazakis, Josh Maine, and Anna Groza at Calif have now published the mechanism in full.

How a Letter on Screen Becomes Memory Corruption

CoreGraphics renders scalable font glyphs by converting their floating-point vector coordinates into a fixed-point sub-pixel format — each pixel is modeled as a 4096×4096 sub-pixel box. The conversion runs through a small inline function called aa_double_to_fixed, which multiplies the coordinate by 4096 and casts the result to a signed 32-bit integer. Before the patch, that cast had no guard: when the scaled value exceeded the int32_t range, the cast behavior in C is undefined, and the clang compiler generated different ARM64 instructions for two adjacent rasterizer functions.

aa_moveto compiled to FCVTZS Wd, Dn, an instruction that saturates at INT32_MAX or INT32_MIN on overflow. aa_lineto used a 64-bit vector conversion, followed by XTN, which truncates — discarding the high 32 bits and producing a sign-wrapped value. That divergence breaks the bounding-box update in aa_add_edges. The function computes the signed direction between consecutive fixed-point endpoints to decide which boundary to expand; when aa_lineto wraps, the direction flips, the wrong branch executes, and the bounding box stops growing to account for the real edge position.

The coverage buffer — the working memory aa_cache_render allocates at the start of each scanline pass — is sized from that bounding box. A corrupted box produces an allocation that is too small. When the renderer then writes alpha values for edges that lie beyond the shrunken box, it writes past the end of the buffer. Calif describes the primitive as a controlled 16-bit increment at an attacker-influenced offset; crucially, whether the buffer lands on the heap or on the stack depends on the apparent bounding-box width, giving an attacker a choice of corruption target.

The vulnerable path requires reaching the bug through CGGlyphBitmapCreateWithPathAndDilation, the only rasterizer entry point that creates its context without device-coordinate clamping flags. The other entry point, ripr_Acquire, sets those flags and would block an out-of-range value before it reached the conversion function. Apple’s fix adds explicit bounds checks inside aa_double_to_fixed itself, applied at all 20-plus sites where the function was inlined across eight aa_* functions.

WhatsApp PDF Delivery and the Zero-Click Question

To identify the delivery format, Calif compared WhatsApp builds 26.37.73 and 26.38.74. Meta’s cross-platform attachment parser, Kaleidoscope — a Rust framework designed to evaluate untrusted file formats before the operating system sees them — gained a new strict-mode flag in the later build: ks_pdf_strict_validation_enabled. The update also added support for parsing embedded FontFile object streams inside PDFs, producing three new defect tags — MalformedFontProgram, UndecodableFontProgram, and UnverifiedFontProgram — any of which routes the file to the WAAttachmentChecker with a high risk score that suppresses automatic rendering.

The WhatsApp change points directly at the attack format. Calif’s crash trace in the PDF case runs from CGContextDrawPDFPageWithOptions through the PDF text-draw operator op_Tj to ripc_DrawGlyphs and finally into CGGlyphBitmapCreateWithPathAndDilation — the unclamped entry point. A PDF that embeds a TrueType font and uses the PDF text matrix alongside composite-glyph scaling transforms can push oversized coordinates all the way to the vulnerable conversion. Calif used an AI agent to generate the crafted font and transform values, then published the full proof-of-concept — including TrueType font generation scripts, a sample harness, and a Makefile — in a GitHub repository.

The firm noted it remains an open question whether the in-the-wild campaign combined CVE-2026-86950 with additional WhatsApp vulnerabilities “to reach parsing with less user interaction” — leaving the zero-click question formally unanswered while making clear the path exists.

Apple’s fix is in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. iOS 27 carries no published CVE entries for this flaw and is not affected. Users on iOS 26 should install the update immediately.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all