Detect Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection in Google Chronicle
Detects exploitation attempts and unpatched-endpoint exposure for CVE-2026-86950, a CWE-787 out-of-bounds write vulnerability affecting the CoreGraphics component across multiple Apple products (iOS, iPadOS, macOS). The flaw is listed in the CISA KEV catalog (BOD 26-04 in scope) and is triggered by processing a maliciously crafted image/PDF, enabling memory corruption and potential arbitrary code execution in the context of the parsing process. Detection strategy combines (1) inventory/telemetry evidence of Apple endpoints running OS builds below the patched versions and (2) behavioral signals of image-parsing crashes, CoreGraphics/ImageIO fault telemetry, and anomalous child-process spawns from renderer/preview processes indicative of exploitation.
MITRE ATT&CK
- Tactic
- Execution Initial Access
YARA-L Detection Query
rule cve_2026_86950_coregraphics_oob_write {
meta:
author = "argus"
cve = "CVE-2026-86950"
severity = "HIGH"
events:
$e.metadata.event_type = "PROCESS_LAUNCH"
$e.principal.hostname = $host
(
$e.principal.process.parent_process.file.full_path = /Preview|QuickLook|Safari|MobileSafari|imagent/ nocase
)
$e.target.process.file.full_path = /(\/sh|\/bash|\/zsh|osascript|ReportCrash|crashpad_handler)/ nocase
match:
$host over 5m
condition:
$e
} Chronicle YARA-L rule matching image-rendering parent processes spawning shells or crash handlers on Apple endpoints, a behavioral indicator of CoreGraphics OOB-write exploitation.
Data Sources
Required Tables
False Positives & Tuning
- Legitimate diagnostic crash handlers launched by rendering apps.
- User-initiated scripting from Safari-based automation.
- Test harnesses generating rendering crashes.
Other platforms for CVE-2026-86950
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Simulate renderer spawning a shell (behavioral proxy)
Expected signal: ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.
- Test 2Generate CoreGraphics-referencing crash artifact
Expected signal: osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.
- Test 3Inventory unpatched-build detection
Expected signal: osquery result event with build not in the patched list.
References (7)
- https://support.apple.com/en-us/149226
- https://support.apple.com/en-us/149228
- https://support.apple.com/en-us/149229
- https://nvd.nist.gov/vuln/detail/CVE-2026-86950
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
- https://isc.sans.edu/diary/rss/33376
Response Playbook
Triage
- Confirm the affected endpoint's exact OS product and build via MDM/osquery inventory and compare against Apple's patched builds referenced in support.apple.com advisories (149226/149228/149229).
- Determine whether the endpoint recently processed untrusted images, PDFs, or messages (Mail/Messages attachments, browsed sites) around the alert time.
- Review CoreGraphics/ImageIO crash reports in the macOS crash logs and correlate with any child process spawned by Preview/QuickLook/Safari.
- Check the CISA KEV entry and BOD 26-04 applicability to determine remediation deadline for federal in-scope assets.
Containment
- Isolate the endpoint from the network via EDR containment if exploitation indicators (shell spawn from renderer, unexpected outbound connections) are present.
- Block delivery of the suspected malicious image/PDF at the mail gateway and web proxy, and quarantine the sample.
- Enforce accelerated OS patch deployment to the affected Apple build across the fleet via MDM.
Evidence Collection
- Preserve macOS crash reports (~/Library/Logs/DiagnosticReports and /Library/Logs/DiagnosticReports) referencing CoreGraphics/ImageIO.
- Capture the triggering image/PDF sample, unified logs (log collect), and EDR process/network telemetry for the alert window.
Escalation Criteria
- !Escalate to incident response if a renderer process spawned a shell, scripting interpreter, or established outbound C2 connections.
- !Escalate to vulnerability management leadership if unpatched in-scope assets exceed the BOD 26-04 remediation deadline.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
macOS DiagnosticReports crash logs referencing CoreGraphics/ImageIO - >
Quarantined malicious image/PDF samples and their download provenance (com.apple.quarantine xattr) - >
Unified log entries for the rendering process and any spawned child processes
Tuning Guidance
Maintain an accurate list of Apple patched builds from the referenced advisories and update the PatchedBuilds/patched_build lists as new point releases ship. Suppress known-benign crash-reporter processes and developer/QA hosts. Prioritize behavioral (renderer-spawns-shell) alerts over pure inventory alerts to reduce noise, and weight inventory-only findings toward vulnerability management rather than SOC triage.
Hunting Queries
Hunts for image-rendering processes spawning shells and for CoreGraphics/ImageIO crash artifacts across the fleet.
DeviceProcessEvents | where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","Safari","MobileSafari") | where FileName in~ ("sh","bash","zsh","osascript") | project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine index=osquery sourcetype="osquery:results" name="crashes" (path="*CoreGraphics*" OR path="*ImageIO*") | table host, crash_path, responsible_proc, _time Atomic Red Team Tests
Emulates the post-exploitation signal of an image-rendering process launching a shell without exploiting the actual vulnerability.
Command
osascript -e 'do shell script "echo cve-2026-86950-sim > /tmp/cg_oob_sim.txt"' Cleanup
rm -f /tmp/cg_oob_sim.txt Expected Telemetry
ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.
Expected Detection
Behavioral rules matching renderer-parent-to-shell child process should fire.
Writes a synthetic crash report referencing CoreGraphics to validate crash-log ingestion and correlation.
Command
mkdir -p ~/Library/Logs/DiagnosticReports && printf 'Process: Preview\nBinary Images:\n CoreGraphics OOB simulated\n' > ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash Cleanup
rm -f ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash Expected Telemetry
osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.
Expected Detection
SPL/Sumo crash-correlation queries should return the host.
Reports a below-patch OS build via osquery to exercise the unpatched-endpoint inventory detection path.
Command
osqueryi --json "SELECT '23A200' AS build, 'macos' AS os_platform, 'testhost' AS host;" Cleanup
true Expected Telemetry
osquery result event with build not in the patched list.
Expected Detection
Inventory-based KQL/SPL queries flag the host as LikelyUnpatched.