A 0-day vulnerability affecting iPhones, iPads and Macs
On the 28th September 2026, Apple published an advisory about a security update fixing a new vulnerability in CoreGraphics, a system component used to display pictures and PDF files. According to Apple, “this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27”. Moreover, the attack involved a “maliciously crafted file”.
Two days later, Calif released a post giving technical details about the vulnerability after reverse-engineering the patch. Their analysis confirmed that the vulnerability lies in the processing of fonts embedded into PDF documents. In a nutshell, specially crafted glyphs in a font file may be too large and overflow some buffers in the CoreGraphics library, leading to potential code execution.
Moreover, they published code to generate a PoC file.
How to detect PDF files exploiting CVE-2026-86950?
Thanks to the exploit description, the PoC file and the help of AI, I managed to develop a python script to detect potential exploits for this vulnerability. The script uses pikepdf to parse PDF files and extract all embedded fonts. Then it parses fonts using fontTools. Finally the script analyses glyphs in the font to detect if any of them matches the characteristics of the exploit. The PoC file trigger.pdf published by Calif is well detected:
detect_cve_2026_86950.py trigger.pdf
[EXPLOIT DETECTED] trigger.pdf
- glyph 'A' outline extends 1000x the em square (16379501 font units) -- impossible for a legitimate glyph
- glyph 'A' real extent is 409488x its declared bounding box (declared max 40) -- the bounding-box 'lie' the exploit relies on
- deep composite-glyph nesting (depth 9) combined with up-scaling components (max scale 511.8594) -- the coordinate amplification chain used to overflow the fixed-point conversion
- 4096 x device coordinate reaches 4.19e+09 at text size 1024, overflowing int32 (> 2147483647) -- the CVE-2026-86950 fixed-point overflow is triggerable
I tested this detection tool on more than 19000 legitimate PDF files collected thanks to CommonCrawl. No false positive was triggered, so the detection algorithm looks pretty solid. However, the tool may be slow (1-500 ms per file, up to a couple seconds in rare cases) due to all the processing implemented in Python. It should be possible to optimize the detection algorithm and to implement it in a compiled language to make it faster.
Due to the nature of the vulnerability, it is very unlikely that exploits can be detected using YARA rules because there is no specific pattern appearing in the file. I think PDF and font parsing are required to detect CVE-2026-86950 exploits reliably.
The detection tool is published in this repository. Please test it and tell me if it works or report issues.
How to use the tool in your own Python code
The detection algorithm can be used in any Python script or application by calling the analyse_pdf function and checking the verdict and error attributes of the returned report object:
import sys
from detect_cve_2026_86950 import analyze_pdf
filepath = sys.argv[1]
print(f"File: {filepath}")
report = analyze_pdf(filepath)
if report.verdict == "exploit":
print ("Potential CVE-2026-86950 exploit detected !")
elif report.verdict == "suspicious":
print ("Suspicious PDF file, but CVE-2026-86950 exploit not confirmed.")
elif report.verdict == "clean":
print ("Clean PDF file - no CVE-2026-86950 exploit detected.")
elif report.verdict == "error":
print (f"Parsing error: {report.error} - No CVE-2026-86950 exploit detected, PDF file looks clean.")