Apple Patches iOS Flaw That Could Let Attackers Run Malicious Code on iPhones

Zusammenfassung:Apple released a security update after confirming an iOS vulnerability may have been exploited in highly sophisticated targeted attacks. Apple has

Apple released a security update after confirming an iOS vulnerability may have been exploited in highly sophisticated targeted attacks.

Apple has released iOS 26.7.1 and iPadOS 26.7.1 on September 28th with a security fix for a serious vulnerability that could allow attackers to run arbitrary code on affected devices.

The tech giant said the issue involves an out-of-bounds write in CoreGraphics and added that the flaw could be triggered by processing a specially crafted file.

SlowMist Warns Crypto Users

Apple confirmed that it may have been exploited in an “extremely sophisticated attack” against specific targeted individuals on iOS versions before iOS 27.

Meanwhile, SlowMist said the vulnerability is relevant to iOS attack activity it has been tracking. The security firm also warned that crypto users should pay particular attention. It urged them to update their Apple devices and avoid suspicious links, files, and app installation prompts. Users should also be careful when downloading apps or opening content from unknown sources.

The vulnerability affects a range of Apple devices, including iPhone 11 and later models, along with several recent iPad models.

Malicious FomoPeek iOS App

A week earlier, SlowMist had reported an iOS-related security threat involving the FomoPeek app. The security firm said it received multiple reports of users losing digital assets and found that affected users had suffered private key exposure. Some had previously installed FomoPeek versions 1.1 and 1.2.

A joint investigation by SlowMist and OKXs security teams found malicious code inside the app. According to the investigation, FomoPeek contained an iOS kernel exploitation framework with eight attack methods. The framework could reportedly select an exploit based on the device model and iOS version.

You may also like:

Affected versions included iOS 12.0-18.7 and iOS 26.0-26.1. If successful, the exploit could escape the iOS sandbox and access Keychain data and files from other apps. This could expose private keys, seed phrases, login credentials, as well as other sensitive information. Hidden server connections were also found that could receive remote commands, with the attack functionality reportedly running automatically at regular intervals.

Earlier this year, Apple was sued by three people for allegedly promoting a fake version of the Sparrow Wallet crypto app through its App Store. The fake app reportedly drained a total of $1.8 million from the victims wallets between May and August 2025.

Haftungsausschluss

Die Ansichten in diesem Artikel stellen nur die persönlichen Ansichten des Autors dar und stellen keine Anlageberatung der Plattform dar. Diese Plattform übernimmt keine Garantie für die Richtigkeit, Vollständigkeit und Aktualität der Artikelinformationen und haftet auch nicht für Verluste, die durch die Nutzung oder das Vertrauen der Artikelinformationen verursacht werden.
Letzter Artikel

Jamie Dimon: Der USD bleibt nur führend, wenn die USA Handelsabkommen schließen

Nächste

Jim Cramer: Die eigentliche Gefahr beim KI-Handel ist die Erzählung, nicht die Ausgaben