ME News reports that on September 19 (UTC+8), 23pds, Chief Information Security Officer at SlowMist, posted on X that cybercriminals have now established a complete attack chain targeting iOS users: clicking a link extracts private keys and seed phrases; when users access websites via Safari, memory corruption in WebKit/JSC grants JavaScript-layer read/write capabilities; PAC bypass enables native function calls; escape from the WebContent sandbox; and kernel privilege escalation to obtain root access, allowing extraction of Keychain and wallet data. Affected versions include iOS 13 through 16.5; iOS users are advised to upgrade immediately. (Source: ChainCatcher)
SlowMist: iOS 13 to 26.5 Users Vulnerable to Black-Grey Industry Attack Chain
KuCoinFlashShare
On-chain news reveals that iOS users from version 13 to 26.5 are being targeted by a black-market industry chain. The exploit leverages WebKit/JSC memory corruption to extract private keys and mnemonic phrases. Attackers bypass PAC, escape the WebContent sandbox, and escalate privileges to root level to steal Keychain and wallet data. SlowMist’s 23pds urges users to upgrade immediately. Industry trends indicate a growing threat landscape in mobile security.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.



