# Researchers release crash demonstration for patched Apple PDF flaw

_Published Thursday, October 1, 2026 at 4:06 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers release crash demonstration for patched Apple PDF flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5u07cHr0A83x9aQdJE-_Emw6K1GzjR2eybdv9Rq_qi43Oi-M2U4eWqCkjvH5fUhw5wKSa-rvQ81gePKLYCqJXyrZpWHXOehEFq_QaTdYpy0O3LLUQGGYn1pxlUGUXwplloAHT3ZP7oMcF6al9A7q9XfnYNUhtBD0qw-GOWuKiyZl8zbrudyjWtEzHXC0/s1700-nu-rw-lo-l85-e365/apple-whatsapp.jpg)

Security researchers at Calif published a public proof of concept on September 30 for CVE-2026-86950, an Apple CoreGraphics flaw that Apple says may have been used against targeted individuals. A PDF containing a crafted font crashes unpatched systems; the researchers report effects on iPhones and Macs.

The flaw causes Apple's graphics framework to allocate a buffer too small for a glyph and write outside it. Calif released generation scripts and a sample PDF, but did not demonstrate code execution or a WhatsApp delivery path.

Apple patched the flaw on September 28. CISA added it to its Known Exploited Vulnerabilities catalog the following day, requiring federal agencies to apply the fix by October 2.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html)

---
Canonical: https://techandbusiness.org/newswire/YpDSMS0Rok2eG1R-BlBZJ9
Published: 2026-10-01T08:06:35.616Z
Story chronology: 2026-09-30T00:00:00.000Z
Retrieved: 2026-10-01T10:37:26.208Z
Publisher: Tech & Business (techandbusiness.org)
