Coruna / DarkSword is being used in the wild.
Attackers socially engineer a Safari click, then walk the full chain: WebKit/JSC memory corruption β PAC bypass β sandbox escape β kernel/root. From there they pull Keychain + wallet data and drain seeds / private keys.
In plaintext, you visit a website and lose your crypto.
If your seed lives on an iPhone, treat this as a wake-up.
Get a hardware wallet. (and update iOS).
Urgent security advisory for iOS users!
Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones.
The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges.
With that access, attackers can pull data from the device Keychain and from local crypto wallet apps.
The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.