吴说区块链|Sep 19, 2026 11:34
Wu Blockchain has learned that SlowMist Security's Chief Information Security Officer, 23pds, has issued a security alert, urging iOS users to upgrade their systems immediately. He pointed out that malicious actors have now developed a full-chain exploit to steal private keys and mnemonic phrases from iOS devices.
The entire attack path includes: using social engineering or watering hole attacks to lure users into visiting malicious websites via Safari, exploiting WebKit/JavaScriptCore (JSC) memory corruption to gain read/write permissions at the JS layer, bypassing Pointer Authentication Code (PAC) defenses to achieve native call capabilities, escaping the WebContent sandbox, and escalating kernel privileges to obtain root access. This allows attackers to steal data from the Keychain and encrypted wallet applications.
The attack stems from the previously leaked "DarkSword" iOS full-chain exploit kit, which has been repurposed by malicious actors due to the leaked materials, posing a severe threat to the security of mobile self-custody wallets.
https://www.(wublock123.com)/news/slowmist-ciso-warns-ios-users-chainwide-exploit-kit-upgrade-now-68669
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink