SlowMist warns that an attack chain targeting iOS users may steal private keys and recovery phrases when victims click on a malicious link. Affected versions are listed as iOS 13 through iOS 26.5.

An attack chain begins when a user accesses a website using Safari. A vulnerability in WebKit/JSC allows an attacker to read and write within the JavaScript layer, then bypass PAC, escape the WebContent sandbox area, and elevate privileges to root.

With this level of access, an attacker can extract data from the Keychain and wallet, including the private key and the recovery phrase. There is currently no additional information about the identities of the groups behind the campaign or the number of devices affected.

iOS users are recommended to update their devices to the latest version.

Source: https://tintucbitcoin.com/slowmist-cho-den-da-tan-cong-toan-dien-nguoi-dung-ios-13-26-5/

Thank you for reading this article!

Like, Comment, and Follow TinTucBitcoin to stay updated with the latest news about the cryptocurrency market and not miss any important information!

$BTC $ETH $BNB $XRP $SOL