Security researchers published a proof-of-concept for CVE-2026-86950, an Apple CoreGraphics vulnerability in PDF processing that crashes iPhones and Macs via malicious embedded fonts. Apple patched the flaw on September 28 after Meta Product Security discovered it, noting potential use in sophisticated attacks. Researchers from Calif found new PDF font-checking code in WhatsApp updates, suggesting it as a possible delivery vector, though no complete exploit chain has been demonstrated.