Apple Patches Critical iPhone Flaw Linked to Crypto Attacks

概要:Apple has patched a critical iPhone vulnerability that may already have been exploited in sophisticated attacks.

Apple has patched a serious iPhone vulnerability that may have already been exploited in highly sophisticated attacks, with blockchain security firm SlowMist warning that the flaw is particularly relevant to cryptocurrency users.

The vulnerability, tracked as CVE-2026-86950, affects Apples CoreGraphics framework and could allow attackers to execute arbitrary code after a device processes a maliciously crafted file.

Apple addressed the issue with the release of iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28. The company said it was aware of a report indicating that the vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals” running versions of iOS released before iOS 27.

Apple described CVE-2026-86950 as an out-of-bounds write vulnerability, meaning malicious data could cause software to write information outside the memory area allocated to it. Such memory-corruption bugs can potentially be leveraged to make a device execute attacker-controlled code.

The vulnerability was reported by Meta Product Security, according to Apple. The company fixed it by introducing improved bounds checking.

Why crypto users could be at risk

Blockchain security firm SlowMist has drawn attention to the update because of recent iOS exploitation activity involving cryptocurrency users.

“Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution,” SlowMist said.

The firm said the patch was “highly relevant” to the iOS attack activity it had previously been tracking.

“For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data,” SlowMist warned.

Importantly, Apple itself has not said that CVE-2026-86950 was specifically used to steal cryptocurrency, nor has SlowMist publicly established that the newly disclosed vulnerability was the exact exploit used in previously investigated wallet thefts.

That warning comes shortly after SlowMist investigated a malicious iOS application called FomoPeek that contained kernel exploits capable of escaping Apple's application sandbox and accessing information belonging to other apps.

According to SlowMist's investigation, malicious versions of FomoPeek were capable of obtaining elevated privileges and potentially accessing Keychain information and files stored by other applications.

The FomoPeek exploit framework reportedly contained multiple attack methods targeting a wide range of iOS releases and was designed to bypass Apple's normal sandbox restrictions.

免責事項

このコンテンツの見解は筆者個人的な見解を示すものに過ぎず、当社の投資アドバイスではありません。当サイトは、記事情報の正確性、完全性、適時性を保証するものではなく、情報の使用または関連コンテンツにより生じた、いかなる損失に対しても責任は負いません。
前へ

WikiBit取引所・資金持ち逃げリスクランキング 第35回:Gemini、株価80%下落・従業員25%削減・欧州市場から全面撤退――「コンプライアンス優等生」はなぜ「崩壊寸前の生存者」になったのか

次へ

イーサリアムの姿が変わる 2027年「ヘゴタ」後に始まる“暗号学的ワールドコンピューター”構想