SlowMist Chief Information Security Officer 23pds said in a post on X that cybercriminal groups have built a complete attack chain against iOS users. According to his description, the process can start when a user clicks a link, leading to the extraction of private keys and seed phrases. When a victim opens a webpage in Safari, the attackers can exploit WebKit/JSC memory corruption to gain JavaScript-layer read and write access, bypass Pointer Authentication Code (PAC) protections to obtain native call capability, break out of the WebContent sandbox, and then escalate privileges in the kernel to gain root access. From there, they can pull data from Keychain and wallet storage. 23pds said affected versions range from iOS 13 to 26.5 and urged iOS users to update as soon as possible.
According to ChainCatcher, SlowMist Chief Information Security Officer 23pds said in a post on X that cybercriminal groups have already put together an attack chain targeting iOS users.
In his description, the chain can begin when a user clicks a link, allowing attackers to extract private keys and seed phrases. If the user visits a webpage through Safari, the attackers can gain JavaScript-layer read and write access through WebKit/JSC memory corruption, then bypass Pointer Authentication Code, or PAC, to obtain native call capability. The chain then breaks out of the WebContent sandbox, escalates privileges at the kernel level to obtain root access, and pulls Keychain and wallet data.
23pds said affected versions include iOS 13 through 26.5 and advised iOS users to upgrade as soon as possible.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.