SlowMist flags iPhone Safari attack chain using six patched DarkSword flaws

SlowMist flags iPhone Safari attack chain using six patched DarkSword flaws

N
News Editor
2026-09-04 12:10:49
SlowMist said it has identified an attack campaign disguised as a free VPS service that targets iPhone Safari on devices running iOS 18.4 through 18.6.2. According to the security team, the attackers chained six vulnerabilities under the codename DarkSword to build a full intrusion path, covering WebKit remote code execution, sandbox escape, and kernel read-write access. The campaign could extract app container files and keychain data without the user noticing, and log keyboard input when wallets such as imToken, TokenPocket, or TronLink were open in the foreground. SlowMist said all six vulnerabilities have already been fixed by Apple and described the activity as reuse of an n-day exploit chain. The team also said that simply visiting a malicious page does not by itself prove that a mnemonic phrase or private key was stolen, and that device forensics would still be required to confirm any compromise. Users on iOS and iPadOS were advised to upgrade to version 18.7.3 or 26.3 and later.

ChainCatcher reported, citing blockchain security firm SlowMist, that it has detected an attack campaign disguised as a free VPS service targeting iPhone Safari on devices running iOS 18.4 to 18.6.2.

SlowMist said the attackers used six vulnerabilities codenamed DarkSword as a complete exploit chain. The chain covered WebKit remote code execution, sandbox escape, and kernel read-write access. It could obtain app container files and keychain data without the user's awareness, and record keyboard input when wallets including imToken, TokenPocket, or TronLink were active in the foreground.

The security team said all six vulnerabilities have now been patched by Apple. It added that the current activity involves reuse of an n-day exploit chain. Visiting a malicious page alone does not directly prove that a mnemonic phrase or private key has been stolen, and device forensics would still be needed for confirmation.

SlowMist advised iOS and iPadOS users to upgrade their systems to version 18.7.3 or 26.3 and later as soon as possible.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.