Apple Patches Critical iPhone Flaw Linked to Crypto Attacks

요약:Apple has patched a critical iPhone vulnerability that may already have been exploited in sophisticated attacks.

Apple has patched a serious iPhone vulnerability that may have already been exploited in highly sophisticated attacks, with blockchain security firm SlowMist warning that the flaw is particularly relevant to cryptocurrency users.

The vulnerability, tracked as CVE-2026-86950, affects Apples CoreGraphics framework and could allow attackers to execute arbitrary code after a device processes a maliciously crafted file.

Apple addressed the issue with the release of iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28. The company said it was aware of a report indicating that the vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals” running versions of iOS released before iOS 27.

Apple described CVE-2026-86950 as an out-of-bounds write vulnerability, meaning malicious data could cause software to write information outside the memory area allocated to it. Such memory-corruption bugs can potentially be leveraged to make a device execute attacker-controlled code.

The vulnerability was reported by Meta Product Security, according to Apple. The company fixed it by introducing improved bounds checking.

Why crypto users could be at risk

Blockchain security firm SlowMist has drawn attention to the update because of recent iOS exploitation activity involving cryptocurrency users.

“Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution,” SlowMist said.

The firm said the patch was “highly relevant” to the iOS attack activity it had previously been tracking.

“For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data,” SlowMist warned.

Importantly, Apple itself has not said that CVE-2026-86950 was specifically used to steal cryptocurrency, nor has SlowMist publicly established that the newly disclosed vulnerability was the exact exploit used in previously investigated wallet thefts.

That warning comes shortly after SlowMist investigated a malicious iOS application called FomoPeek that contained kernel exploits capable of escaping Apple's application sandbox and accessing information belonging to other apps.

According to SlowMist's investigation, malicious versions of FomoPeek were capable of obtaining elevated privileges and potentially accessing Keychain information and files stored by other applications.

The FomoPeek exploit framework reportedly contained multiple attack methods targeting a wide range of iOS releases and was designed to bypass Apple's normal sandbox restrictions.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

NEAR 인텐츠, Bitget 해커들과 연관된 5,000만 달러 차단했다고 밝혀

다음

코인베이스, 암호화폐 무관 신제품 예고…정말 그럴까?