Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets

2 days ago 3



A critical security vulnerability is making its way through Apple’s mobile ecosystem, and the target is not just your photos or messages. Blockchain security firm SlowMist confirmed on September 19 that an active, full-chain exploit is being used against iPhones running iOS 13 through 26.5, with the specific goal of stealing private keys and mnemonic seed phrases from crypto wallets. The attack arrives through something most people do dozens of times a day: visiting a webpage in Safari. That casual tap on a link is all it takes. How the exploit actually works The attack chain begins with a malicious Safari webpage that exploits a memory corruption flaw in WebKit, the browser engine Apple uses across its products, and its JavaScript runtime environment, JavaScriptCore. Once that initial foothold is established, the attacker’s code does not stop there. From that entry point, the exploit navigates through a sequence of escalating privileges. It bypasses Pointer Authentication Codes, which are Apple’s built-in mechanism for verifying that software instructions have not been tampered with. It then breaks out of the browser’s sandbox, the isolated environment designed to keep web content...

Read Entire Article