CVE-2026-86950 Google Chronicle · YARA-L

Detect Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection in Google Chronicle

Detects exploitation attempts and unpatched-endpoint exposure for CVE-2026-86950, a CWE-787 out-of-bounds write vulnerability affecting the CoreGraphics component across multiple Apple products (iOS, iPadOS, macOS). The flaw is listed in the CISA KEV catalog (BOD 26-04 in scope) and is triggered by processing a maliciously crafted image/PDF, enabling memory corruption and potential arbitrary code execution in the context of the parsing process. Detection strategy combines (1) inventory/telemetry evidence of Apple endpoints running OS builds below the patched versions and (2) behavioral signals of image-parsing crashes, CoreGraphics/ImageIO fault telemetry, and anomalous child-process spawns from renderer/preview processes indicative of exploitation.

MITRE ATT&CK

Tactic
Execution Initial Access

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule cve_2026_86950_coregraphics_oob_write {
  meta:
    author = "argus"
    cve = "CVE-2026-86950"
    severity = "HIGH"
  events:
    $e.metadata.event_type = "PROCESS_LAUNCH"
    $e.principal.hostname = $host
    (
      $e.principal.process.parent_process.file.full_path = /Preview|QuickLook|Safari|MobileSafari|imagent/ nocase
    )
    $e.target.process.file.full_path = /(\/sh|\/bash|\/zsh|osascript|ReportCrash|crashpad_handler)/ nocase
  match:
    $host over 5m
  condition:
    $e
}
high severity medium confidence

Chronicle YARA-L rule matching image-rendering parent processes spawning shells or crash handlers on Apple endpoints, a behavioral indicator of CoreGraphics OOB-write exploitation.

Data Sources

Chronicle UDM process launch events (macOS/iOS EDR)

Required Tables

udm.events

False Positives & Tuning

  • Legitimate diagnostic crash handlers launched by rendering apps.
  • User-initiated scripting from Safari-based automation.
  • Test harnesses generating rendering crashes.

Other platforms for CVE-2026-86950


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate renderer spawning a shell (behavioral proxy)

    Expected signal: ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.

  2. Test 2Generate CoreGraphics-referencing crash artifact

    Expected signal: osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.

  3. Test 3Inventory unpatched-build detection

    Expected signal: osquery result event with build not in the patched list.


Response Playbook

Triage

  1. Confirm the affected endpoint's exact OS product and build via MDM/osquery inventory and compare against Apple's patched builds referenced in support.apple.com advisories (149226/149228/149229).
  2. Determine whether the endpoint recently processed untrusted images, PDFs, or messages (Mail/Messages attachments, browsed sites) around the alert time.
  3. Review CoreGraphics/ImageIO crash reports in the macOS crash logs and correlate with any child process spawned by Preview/QuickLook/Safari.
  4. Check the CISA KEV entry and BOD 26-04 applicability to determine remediation deadline for federal in-scope assets.

Containment

  1. Isolate the endpoint from the network via EDR containment if exploitation indicators (shell spawn from renderer, unexpected outbound connections) are present.
  2. Block delivery of the suspected malicious image/PDF at the mail gateway and web proxy, and quarantine the sample.
  3. Enforce accelerated OS patch deployment to the affected Apple build across the fleet via MDM.

Evidence Collection

  1. Preserve macOS crash reports (~/Library/Logs/DiagnosticReports and /Library/Logs/DiagnosticReports) referencing CoreGraphics/ImageIO.
  2. Capture the triggering image/PDF sample, unified logs (log collect), and EDR process/network telemetry for the alert window.

Escalation Criteria

  • !Escalate to incident response if a renderer process spawned a shell, scripting interpreter, or established outbound C2 connections.
  • !Escalate to vulnerability management leadership if unpatched in-scope assets exceed the BOD 26-04 remediation deadline.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >macOS DiagnosticReports crash logs referencing CoreGraphics/ImageIO
  • >Quarantined malicious image/PDF samples and their download provenance (com.apple.quarantine xattr)
  • >Unified log entries for the rendering process and any spawned child processes

Tuning Guidance

Maintain an accurate list of Apple patched builds from the referenced advisories and update the PatchedBuilds/patched_build lists as new point releases ship. Suppress known-benign crash-reporter processes and developer/QA hosts. Prioritize behavioral (renderer-spawns-shell) alerts over pure inventory alerts to reduce noise, and weight inventory-only findings toward vulnerability management rather than SOC triage.


Hunting Queries

Hunts for image-rendering processes spawning shells and for CoreGraphics/ImageIO crash artifacts across the fleet.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","Safari","MobileSafari") | where FileName in~ ("sh","bash","zsh","osascript") | project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine
Hunting — SPL
spl
index=osquery sourcetype="osquery:results" name="crashes" (path="*CoreGraphics*" OR path="*ImageIO*") | table host, crash_path, responsible_proc, _time

Atomic Red Team Tests

Test 1 Simulate renderer spawning a shell (behavioral proxy)
macos

Emulates the post-exploitation signal of an image-rendering process launching a shell without exploiting the actual vulnerability.

Command

bash
osascript -e 'do shell script "echo cve-2026-86950-sim > /tmp/cg_oob_sim.txt"'

Cleanup

bash
rm -f /tmp/cg_oob_sim.txt

Expected Telemetry

ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.

Expected Detection

Behavioral rules matching renderer-parent-to-shell child process should fire.

Test 2 Generate CoreGraphics-referencing crash artifact
macos

Writes a synthetic crash report referencing CoreGraphics to validate crash-log ingestion and correlation.

Command

bash
mkdir -p ~/Library/Logs/DiagnosticReports && printf 'Process: Preview\nBinary Images:\n CoreGraphics OOB simulated\n' > ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash

Cleanup

bash
rm -f ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash

Expected Telemetry

osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.

Expected Detection

SPL/Sumo crash-correlation queries should return the host.

Test 3 Inventory unpatched-build detection
macos

Reports a below-patch OS build via osquery to exercise the unpatched-endpoint inventory detection path.

Command

bash
osqueryi --json "SELECT '23A200' AS build, 'macos' AS os_platform, 'testhost' AS host;"

Cleanup

bash
true

Expected Telemetry

osquery result event with build not in the patched list.

Expected Detection

Inventory-based KQL/SPL queries flag the host as LikelyUnpatched.

Related Detections