CVE-2026-86950: The Great Glyph Grift - An in-the-wild iOS bug with a possible WhatsApp zero-click path
Apple fixed in-the-wild CoreGraphics CVE-2026-86950 in iOS 26.7.1; crafted PDF fonts can trigger an out-of-bounds write.
Apple fixed CVE-2026-86950 in iOS 26.7.1, a CoreGraphics flaw credited to Meta Product Security. Apple said the bug may have been exploited in an extremely sophisticated attack against specific targeted individuals. Calif's patch analysis describes a coordinate unit-conversion error in anti-aliased path rasterization: a malicious PDF containing a crafted font can undersize an allocation and cause an out-of-bounds write, and the researchers say a proof of concept triggers it on macOS and iOS. Later WhatsApp builds added optional strict PDF validation, including checks of embedded FontFile streams.