Tendvane

← All articles

SecurityOctober 1, 2026

The font inside the PDF was the attack, and now anyone can try it

A PDF can take over an iPhone. Not a PDF with a dodgy link in it, not one that asks you to install anything: the file itself, opened, is enough if a font embedded in it has been built the wrong way.

That is CVE-2026-86950, an out-of-bounds write in CoreGraphics, the part of Apple's software that draws things on screen. Apple patched it on 28 September in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, crediting Meta's product security team for the find. Apple's wording was careful: the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals running iOS before version 27. That is the phrasing Apple keeps for spyware. CISA added it to the known exploited list at the end of September and gave US federal agencies until 2 October to patch.

What changed on 30 September is that proof of concept code went public. It crashes unpatched iPhones and Macs with a malformed glyph, which is the loud, harmless half of the same bug. Researchers also noticed new font scanning code in WhatsApp builds 26.37.73 and 26.38.74 and wondered aloud whether messaging was the delivery route, then pulled that claim back as speculation. No attack beyond crashing has been demonstrated.

If you own an iPhone, iPad or Mac, open Settings and let the update install today rather than at the weekend. Targeted spyware is not your problem, but published crash code has a habit of turning into something worse once enough people pick at it. On the Windows machine in the same house the equivalent chore is keeping your PDF reader and browser current, and Tendvane can push both through winget in one pass.

Sources

Download Tendvane