SlowMist Reports iOS Users Vulnerable to Attack Chain from iOS 13 to 16.5

icon MarsBit
Share
AI summary iconSummary
On-chain news reveals a critical iOS attack chain spanning versions 13 to 16.5, as reported by SlowMist. Attackers exploit WebKit/JSC memory corruption through malicious links to extract private keys and mnemonic phrases. They bypass PAC, escape the WebContent sandbox, and escalate privileges to root level to steal Keychain and wallet data. Users are urged to upgrade immediately. Inflation data remains a secondary concern as security risks intensify.

HuoXing Finance reports that 23pds, Chief Information Security Officer at SlowMist, posted on X that cybercriminals have now established a complete attack chain targeting iOS users: clicking a link extracts private keys and seed phrases; when users access websites via Safari, memory corruption in WebKit/JSC grants JavaScript layer read/write capabilities; bypassing PAC enables native function calls; escaping the WebContent sandbox; and escalating kernel privileges to obtain root access, allowing extraction of Keychain and wallet data. Affected versions include iOS 13 through 16.5; iOS users are advised to upgrade immediately.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.