Apple Patches iPhone Zero-Day Critical for Crypto Wallets 

Ledger
Ledger


Apple has patched a zero-day vulnerability in iOS that the company says may have been exploited in an “extremely sophisticated attack” against targeted individuals. 

The vulnerability, tracked as CVE-2026-86950, affects Apple’s CoreGraphics framework, which handles graphics and image processing. Apple says a specially crafted file could trigger an out-of-bounds write and potentially allow arbitrary code execution. The flaw was reported by Meta Product Security and was fixed with improved bounds checking.

Apple Releases Security Update

Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026. The affected devices include iPhone 11 and later, along with several recent iPad models. 

Sponsored

itrust

Crypto Prediction Markets

18+ · Gambling involves risk. Play responsibly.

The update is available for iPhone 11 and later. It also covers the iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later). 

According to company’s report, the flaw could allow a specially crafted file to write data outside its allocated memory, potentially letting an attacker run malicious code on an affected device. Apple fixed the issue with improved bounds checking.

More importantly, the company noted that the flaw may have been exploited in an “extremely sophisticated” attack targeting specific individuals on versions of iOS before iOS 27.

Apple did not provide details about how many people were targeted, when the attacks occurred or whether the attacks were successful.

SlowMist Flags Crypto Wallet Risk

The update has also drawn attention from the cryptocurrency security community. Blockchain security SlowMist partner and CISO noted on X, that vulnerability may be linked to attacks targeting cryptocurrency wallets. Apple has not confirmed that CVE-2026-86950 was used to steal cryptocurrency or wallet credentials.

“”Apple is aware of a report that this issue may have been actively exploited against certain individuals in targeted and highly sophisticated attacks, affecting iOS versions prior to iOS 27,” the message stated.

On September 19, he also warned that dark web operators had developed an attack that could steal private keys and seed phrases simply by opening a webpage in Safari. He said it affected iOS 13 through 26.5, although the exact scope was unclear. Apple and Google have not commented on the claims.

Because many crypto users manage wallets on mobile devices, exploited iOS vulnerabilities can pose a potential risk to sensitive wallet data.

Delve into DailyCoin’s popular crypto news today:
Anthropic IPO Leak Points to New Timeline, Polymarket Odds Rise 
Ripple Eyes $155 Trillion Market Within SWIFT Links





Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*