SlowMist: Hackers Implement Full-Chain iOS Exploit to Steal Private Keys and Mnemonic Phrases Across Versions 13 to 26.5

SlowMist Chief Information Security Officer 23pds has issued an urgent security warning advising all iOS users to update their devices immediately. He disclosed that cybercriminals have actively operationalized a full-chain exploit framework capable of silently exfiltrating private keys and mnemonic seed phrases directly from iOS devices.

The attack execution pathway involves: luring targets to a malicious webpage via Safari through social engineering or watering-hole tactics, triggering memory corruption in WebKit/JavaScriptCore (JSC) to secure arbitrary read/write access at the JavaScript layer, subsequently bypassing Pointer Authentication Codes (PAC) to achieve native code execution, escaping the WebContent sandbox, and completing kernel privilege escalation to root to drain device Keychains and local crypto wallet application data. The potentially affected versions are reported to span iOS 13 through iOS 26.5 (pending final confirmation).

submitted by /u/Project_Demosthenes_ [link] [comments]r/CryptoCurrencyRead More

You might also be interested in reading Tokenized Stock Holders Near 1 Million After 92% Growth in 30 Days.