Zero-day remote code execution vulnerability in iPhone Safari. Click a link, and your crypto, passwords and everything else on your iPhone are gone.
Exploited in the wild by "DarkSword" malware.
"The DarkSword attack program has leaked, with its core capability being: extracting forensic-level data from iOS devices via HTTP interfaces. In actual attacks, attackers can combine social engineering or watering hole attacks to lure users into falling victim, thereby stealing data from iPhone / iPad devices and uploading it to servers controlled by the attackers."
Update iPhones immediately. Apple originally patched this, but rumours suggest even the latest versions are vulnerable, “pending confirmation,” across a wider range than the original 18.4–18.7 window.
From a Chinese security researcher, SlowMist CISO,
@im23pds
nitter.net/im23pds/status/2101265…
Urgent security advisory for iOS users!
Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones.
The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges.
With that access, attackers can pull data from the device Keychain and from local crypto wallet apps.
The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.