In-the-wild iOS bug CVE-2026-86950 traced to compiler optimization causing OOB write
jedisct1 · x · 2026-10-01
Apple's iOS 26.7.1 fixed CoreGraphics bug CVE-2026-86950, which it said "may have been exploited in an extremely sophisticated attack against specific targeted individuals" — reported by Meta Product Security with a possible WhatsApp zero-click path. Calif researchers reverse-engineered the patch: a compiler optimization introduced a unit conversion error, so CoreGraphics undersizes an allocation when rendering a specially crafted font in a PDF, leading to an out-of-bounds write. A PoC works on both macOS and iOS.
More from Safety
- Flag Game paper uses a flag-guessing toy model to trace how AI agent swarms spread shared misconceptions — Hidenori8Tanaka · 2026-10-02
- OpenSwitchboard: open-source MCP server gates agent commitments behind human presses — EnvironmentalRice348 · 2026-10-02
- Buyers now fill out export control declarations when purchasing RTX 5090s in stores — blelbach · 2026-10-02
- Viral analogy asks: why do we release AI like cars, with liability only after failure — aronchick · 2026-10-02
- Ex-OpenAI policy lead: we may never eval dangerous AI capabilities well enough — RosieCampbell · 2026-10-02
- Trump likely to pick Jay Clayton as White House AI czar, CBS News reports — ShakeelHashim · 2026-10-02