Security researchers published a proof-of-concept for CVE-2026-86950, an Apple CoreGraphics vulnerability in PDF processing that crashes iPhones and Macs via malicious embedded fonts. Apple patched the flaw on September 28 after Meta Product Security discovered it, noting potential use in sophisticated attacks. Researchers from Calif found new PDF font-checking code in WhatsApp updates, suggesting it as a possible delivery vector, though no complete exploit chain has been demonstrated.
Apple patched a CoreGraphics vulnerability (CVE-2026-86950) in iOS 26.7.1 that was exploited in the wild against targeted individuals. Researchers identified a unit conversion error in font rendering that allows out-of-bounds writes via malicious PDFs, with evidence suggesting exploitation through WhatsApp's attachment handling.
A developer built a WhatsApp client for Emacs on macOS by reading the app's local SQLite database and using the macOS Shortcuts app to send messages, avoiding Meta's lack of official API while keeping the account secure.
Apple patched CVE-2026-86950, a unit conversion error in CoreGraphics triggered by malicious PDFs with crafted fonts, causing out-of-bounds memory writes. The vulnerability was exploited in the wild targeting specific individuals and may have a zero-click WhatsApp attack vector. Meta researchers discovered the bug through patch analysis and found WhatsApp added strict PDF validation to detect malformed fonts.
Preserve.Chat is a free tool that converts WhatsApp chat exports into shareable, readable web links. Users can upload exports, search for specific messages, select a date range or message range to share, and customize the display style while controlling privacy by excluding sensitive details.
Android 17 QPR2 Beta 6.1 adds HiLight message notification support to Pixel 11 Pro devices, allowing the LED to glow when favorite contacts send messages through Google Messages and WhatsApp. The feature is accessible via Settings and marks a significant addition ahead of the stable December release.
Germany's Customs Office has exploited device linking features in WhatsApp and Signal to eavesdrop on suspects by connecting police-controlled computers to their accounts without cracking encryption. The technique requires physical phone access or intercepting verification codes through phishing or SMS interception. Security experts advocate for displaying connected devices to help users detect unauthorized access.
Meta is expanding its Private Processing confidential computing infrastructure to AI glasses, enabling cloud-based AI models to process user requests without Meta accessing the data. The system uses Trusted Execution Environments to encrypt data in use, implements anonymous credentials and third-party relays to prevent metadata leakage, and includes public verifiability through a transparency ledger. Meta previously deployed Private Processing for WhatsApp and Meta AI in 2025.