SlowMist: Hackers Implement Full-Chain iOS Exploit to Steal Private Keys and Mnemonic Phrases Across Versions 13 to 26.5
SlowMist Chief Information Security Officer 23pds has issued an urgent security warning advising all iOS users to update their devices immediately. He disclosed that cybercriminals have actively operationalized a full-chain exploit framework capable of silently exfiltrating private keys and mnemonic seed phrases directly from iOS devices.
The attack execution pathway involves: luring targets to a malicious webpage via Safari through social engineering or watering-hole tactics, triggering memory corruption in WebKit/JavaScriptCore (JSC) to secure arbitrary read/write access at the JavaScript layer, subsequently bypassing Pointer Authentication Codes (PAC) to achieve native code execution, escaping the WebContent sandbox, and completing kernel privilege escalation to root to drain device Keychains and local crypto wallet application data. The potentially affected versions are reported to span iOS 13 through iOS 26.5 (pending final confirmation).
[link] [comments]
You can get bonuses upto $100 FREE BONUS when you:
π° Install these recommended apps:
π² SocialGood - 100% Crypto Back on Everyday Shopping
π² xPortal - The DeFi For The Next Billion
π² CryptoTab Browser - Lightweight, fast, and ready to mine!
π° Register on these recommended exchanges:
π‘ Binanceπ‘ Bitfinexπ‘ Bitmartπ‘ Bittrexπ‘ Bitget
π‘ CoinExπ‘ Crypto.comπ‘ Gate.ioπ‘ Huobiπ‘ Kucoin.
Comments