吴说区块链|9月 04, 2026 12:01
WuTalk has learned from the SlowMist security team that they have uncovered an attack disguised as a free VPS service. The related webpage targets iPhones running iOS 18.4–18.6.2 Safari, leveraging the DarkSword six-vulnerability chain to launch multi-stage attacks, including WebKit RCE, sandbox escape, and kernel read/write. Once the attack succeeds, it can collect app container files, keychain data, and record keyboard inputs when imToken, TokenPocket, or TronLink are in the foreground. SlowMist stated that all six vulnerabilities have already been patched by Apple, and the current attack involves the reuse of n-day vulnerability chains. Simply visiting the related webpage does not confirm that mnemonic phrases or private keys have been stolen; device forensics are still required for confirmation. Users are advised to upgrade to iOS/iPadOS 18.7.3 or 26.3 and above.
https://(wublock123.com)/news/manyi-discloses-ios-safari-darksword-malware-steals-files-keychain-wallet-inputs-67830
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink