SlowMist warns of active full-chain iOS exploit affecting versions 13–26.5 that silently exfiltrates private keys and seed phrases via WebKit memory corruption and kernel privilege escalation.
Security & Exploits ·
SlowMist's Chief Information Security Officer 23pds has warned of an active full-chain iOS exploit that can silently steal private keys and seed phrases from affected devices. According to the advisory, the vulnerability chain spans iOS versions 13 through 26.5, pending final confirmation, and cybercriminals have already begun deploying it in the wild.
The attack begins when users are directed to a malicious webpage via Safari, typically through social engineering or watering-hole campaigns. Once on the site, the exploit triggers memory corruption in WebKit/JavaScriptCore to gain arbitrary read/write access at the JavaScript layer, then bypasses Pointer Authentication Codes to achieve native code execution and escape the WebContent sandbox. The final stage involves kernel privilege escalation to root access, which allows attackers to drain device Keychains and extract data from local cryptocurrency wallet applications.
The advisory urges all iOS users to update their devices immediately. What remains unclear is whether Apple has released patches for the affected versions, how many users or wallets have been compromised, or the specific attack surface in production environments.