SlowMist warns DarkSword iOS exploit is now being used in real attacks

SlowMist warns DarkSword iOS exploit is now being used in real attacks

N
News Editor
2026-09-19 11:07:07
SlowMist Chief Information Security Officer 23pds warned iOS users on Sept. 19 to update to the latest system version after saying the DarkSword iOS attack tool, which was leaked in March, is now being used by black-market operators in real-world attacks. According to the alert, attackers can trick users into opening a malicious webpage in Safari, then gradually break out of the browser sandbox and escalate privileges. The attack chain could eventually access keychain data and wallet information, allowing the theft of private keys and seed phrases. 23pds said the suspected affected range is iOS 13 to 26.5, though that scope has not been confirmed.

BlockBeats reported on Sept. 19 that SlowMist Chief Information Security Officer 23pds warned iOS users to update to the latest system version.

23pds said the DarkSword iOS attack tool, which was leaked in March, is now being used in real attacks by black-market operators. In the described attack flow, victims can be lured into opening a malicious webpage in Safari. The attacker then gradually escapes the browser sandbox and gains higher privileges, eventually accessing keychain data and wallet information to steal private keys and seed phrases.

The suspected affected range is iOS 13 to 26.5, though that remains unconfirmed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1000

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.