Apple Patches iOS Flaw That Could Let Attackers Run Malicious Code on iPhones

요약:Apple released a security update after confirming an iOS vulnerability may have been exploited in highly sophisticated targeted attacks. Apple has

Apple released a security update after confirming an iOS vulnerability may have been exploited in highly sophisticated targeted attacks.

Apple has released iOS 26.7.1 and iPadOS 26.7.1 on September 28th with a security fix for a serious vulnerability that could allow attackers to run arbitrary code on affected devices.

The tech giant said the issue involves an out-of-bounds write in CoreGraphics and added that the flaw could be triggered by processing a specially crafted file.

SlowMist Warns Crypto Users

Apple confirmed that it may have been exploited in an “extremely sophisticated attack” against specific targeted individuals on iOS versions before iOS 27.

Meanwhile, SlowMist said the vulnerability is relevant to iOS attack activity it has been tracking. The security firm also warned that crypto users should pay particular attention. It urged them to update their Apple devices and avoid suspicious links, files, and app installation prompts. Users should also be careful when downloading apps or opening content from unknown sources.

The vulnerability affects a range of Apple devices, including iPhone 11 and later models, along with several recent iPad models.

Malicious FomoPeek iOS App

A week earlier, SlowMist had reported an iOS-related security threat involving the FomoPeek app. The security firm said it received multiple reports of users losing digital assets and found that affected users had suffered private key exposure. Some had previously installed FomoPeek versions 1.1 and 1.2.

A joint investigation by SlowMist and OKXs security teams found malicious code inside the app. According to the investigation, FomoPeek contained an iOS kernel exploitation framework with eight attack methods. The framework could reportedly select an exploit based on the device model and iOS version.

You may also like:

Affected versions included iOS 12.0-18.7 and iOS 26.0-26.1. If successful, the exploit could escape the iOS sandbox and access Keychain data and files from other apps. This could expose private keys, seed phrases, login credentials, as well as other sensitive information. Hidden server connections were also found that could receive remote commands, with the attack functionality reportedly running automatically at regular intervals.

Earlier this year, Apple was sued by three people for allegedly promoting a fake version of the Sparrow Wallet crypto app through its App Store. The fake app reportedly drained a total of $1.8 million from the victims wallets between May and August 2025.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

앤드루 쿠오모, 민주당 의회 승리 시 암호화폐 규제 무너질 수 있다