星球日报|Sep 04, 2026 12:10
[SlowMist: iOS Safari DarkSword Attack Can Steal Wallet Inputs, Zero-Click Triggers Six Vulnerability Chain]
Odaily Planet Daily News – According to the SlowMist security team, they have detected an attack disguised as a free VPS service, specifically targeting the Safari browser on iPhones running iOS versions 18.4 to 18.6.2. The attackers utilized a six-vulnerability chain, codenamed DarkSword, to form a complete attack chain, encompassing WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files, keychain data, and record keyboard inputs when wallets like imToken, TokenPocket, or TronLink are in the foreground, all without the user's awareness.
The SlowMist team stated that all six vulnerabilities have already been patched by Apple, and the current attack involves the reuse of an n-day vulnerability chain. Simply visiting a malicious page does not directly confirm that mnemonic phrases or private keys have been stolen; device forensics are still required for confirmation. iOS/iPadOS users are advised to promptly update their systems to version 18.7.3, 26.3, or later.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink