Apple patches iOS vulnerability, are crypto wallets still at risk?

fiverr
fiverr



Apple has patched an iPhone and iPad vulnerability that may already have been used in highly targeted attacks, prompting blockchain security researchers to warn cryptocurrency users to update affected devices.

Summary

  • Apple released iOS 26.7.1 fixing CVE-2026-86950, a CoreGraphics flaw that can enable arbitrary code execution.
  • Apple says the vulnerability may have been exploited against specifically targeted users before iOS 27.
  • SlowMist warns crypto users because recent iOS exploitation activity has targeted sensitive wallet information directly.
  • Meta Product Security reported CVE-2026-86950, while Apple fixed it using improved bounds checking protections internally.
  • Apple has not confirmed CVE-2026-86950 was used to steal cryptocurrency or drain crypto wallets directly.

Apple said on Sept. 28 that CVE-2026-86950 affects CoreGraphics and can allow arbitrary code execution when a device processes a maliciously crafted file. The flaw was fixed in iOS 26.7.1 and iPadOS 26.7.1 through improved bounds checking.

Phemex

The company said it was aware of a report indicating the vulnerability “may have been exploited in an extremely sophisticated attack” against specific targeted individuals using iOS versions released before iOS 27. Apple credited Meta Product Security with reporting the issue.

Blockchain security firm SlowMist subsequently warned that the patch was particularly relevant to cryptocurrency holders because researchers have recently tracked iOS attacks capable of reaching sensitive wallet information. The firm has not publicly demonstrated that CVE-2026-86950 was the vulnerability used in those earlier crypto incidents.

Apple says the iPhone flaw can execute attacker code

CVE-2026-86950 is an out-of-bounds write vulnerability in CoreGraphics, the Apple framework responsible for handling and rendering graphical content.

Apple explained that processing a maliciously crafted file could result in arbitrary code execution. An out-of-bounds write occurs when software writes data beyond an allocated memory area, creating conditions that attackers can potentially use to corrupt memory or run their own code.

The company did not describe the file format used in known attacks, identify the targets or disclose how attackers delivered the malicious content. Its advisory does not attribute the attacks to a particular hacking group, commercial surveillance vendor or financially motivated operation.

Affected devices include the iPhone 11 and later models, along with supported iPad Pro, iPad Air, iPad and iPad mini models still running the iOS 26 or iPadOS 26 branch. Apple’s current security release list shows iOS 27.0.1 and iPadOS 27.0.1 as the latest releases for supported newer devices.

CVE-2026-86950 reaches beyond iPhones and iPads. Apple patched the same CoreGraphics vulnerability in macOS Sequoia 15.8.1, while macOS Tahoe 26.7.1 received the corresponding fix.

Apple’s wording indicates that exploitation occurred before the vulnerability became publicly documented, fitting the common description of a zero-day exploit. The company itself refers to the CVE and possible exploitation without applying the “zero-day” label in its advisory.

SlowMist links the warning to recent crypto wallet threats

For crypto users, the concern comes from a series of recent attempts to defeat iOS protections and reach data stored by cryptocurrency applications.

SlowMist warned after Apple released the patch that recent iOS exploitation activity had targeted sensitive wallet data. The security company stopped short of confirming that CVE-2026-86950 powered any previously documented wallet theft.

One recent case involved FomoPeek, an iOS application investigated after reports of cryptocurrency losses and private-key exposure. As crypto.news previously reported, malicious FomoPeek versions contained an iOS kernel exploitation framework capable of reaching crypto wallet data.

Researchers examining FomoPeek versions 1.1 and 1.2 found code designed to exploit several iOS versions, escape Apple’s application sandbox and access information normally isolated from other apps. The framework could potentially reach Keychain records, private keys, seed phrases, account credentials and locally stored files, according to the security analysis cited in the report.

The malicious FomoPeek versions are a separate security event. Available research does not establish CVE-2026-86950 as one of the vulnerabilities used by the application.

Binance advised users who had installed affected FomoPeek versions to remove the application, update iOS and move self-custodied crypto into a new wallet generated on a clean device if sensitive credentials may have been exposed.

Another iOS exploit chain has raised wallet concerns

SlowMist has separately tracked Darksword, an advanced iOS exploit framework that researchers say can compromise devices after targets open malicious links.

In related coverage, SlowMist warned that Darksword may have been adapted to attack crypto wallets on iOS 26.5, although Apple and Google have not independently confirmed the reported iOS 26.5 capability.

The documented Darksword framework combines multiple vulnerabilities to bypass iOS defenses and install additional payloads. Earlier research connected different versions of the framework to campaigns targeting users in several countries.

After obtaining elevated device access, attackers could potentially collect messages, browser history, account information, location data and records associated with cryptocurrency wallets. SlowMist CISO 23pds warned that private keys held locally could be among the data exposed when attackers gain high-level access to a device.

No public evidence reviewed so far establishes that CVE-2026-86950 forms part of Darksword. The newly patched CoreGraphics issue and the earlier Darksword research should therefore be treated as separate findings unless Apple, Meta, SlowMist or another security researcher produces technical evidence linking them.

The same distinction applies to FomoPeek. Both earlier cases demonstrate why cryptocurrency security researchers are paying close attention to iOS exploitation, but neither proves that Apple’s newly disclosed CVE was used to drain a wallet.

Apple has not confirmed crypto theft through CVE-2026-86950

Apple’s disclosure establishes two core facts: CVE-2026-86950 can lead to arbitrary code execution, and the company received a report that the flaw may have been exploited against targeted individuals before iOS 27.

The advisory does not mention cryptocurrency, digital wallets, seed phrases or private keys. Apple has not disclosed the identity of any victim or provided a monetary loss connected to the flaw.

SlowMist’s warning adds crypto-specific context because the security firm has recently investigated device-level attacks capable of reaching wallet information. Its comments do not establish that CVE-2026-86950 itself was the exploit responsible for any known cryptocurrency loss.

Apple’s latest security records show iOS 26.7.1 and iPadOS 26.7.1 were released specifically with the CoreGraphics correction on Sept. 28. The company’s iOS 27.0.1 release appeared on the same date, while Apple said the known targeted exploitation affected versions before iOS 27.

Users remaining on the iOS 26 branch can install iOS 26.7.1 on eligible hardware. Apple’s advisory identifies iPhone 11 and later among the supported devices receiving the patch, alongside multiple generations of iPad Pro, iPad Air, standard iPad and iPad mini.

For users previously exposed to malicious wallet software, installing an operating-system patch does not reverse any earlier disclosure of a seed phrase or private key. In its FomoPeek warning, Binance recommended creating fresh credentials on an uncompromised device and moving funds when wallet secrets may already have been obtained.

Apple has not published further details about the individuals targeted through CVE-2026-86950, the malicious files used in the attacks or whether additional vulnerabilities were combined with the CoreGraphics flaw.





Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*