Apple has patched a serious iPhone vulnerability. Blockchain security company SlowMist warns that this vulnerability is particularly relevant to cryptocurrency users.
The vulnerability is identified as CVE-2026-86950 and affects Apple's CoreGraphics framework. After a device processes a maliciously constructed file, an attacker may be able to execute arbitrary code.
On September 28, Apple released iOS 26.7.1 and iPadOS 26.7.1 to fix this issue. The company stated that they had become aware of a report indicating that the vulnerability "may have been exploited in extremely complex attacks targeting specific individuals running versions of iOS prior to iOS 27."
Apple describes CVE-2026-86950 as a buffer overflow write vulnerability, which means that malicious data could cause the software to write information outside of the memory area allocated to it. Such memory corruption vulnerabilities could be exploited to make the device execute code controlled by the attacker.
Apple stated that the vulnerability was reported by Meta Product Security. The company fixed this issue by improving boundary checks.
Why Cryptocurrency Users May Face Risks
The blockchain security company SlowMist is paying attention to this update because of recent activities involving iOS that target cryptocurrency users.
SlowMist Apple has released an important iOS / iPadOS 26.7.1 security update, which fixes CVE-2026-86950, a buffer overflow write vulnerability that could potentially allow arbitrary code execution.
The company stated that this patch is "highly relevant" to the iOS attack activities they had previously tracked.
SlowMist warns, "This is particularly concerning for cryptocurrency users, as the iOS exploitation activities we have observed are targeting sensitive wallet data."
Importantly, Apple itself has not stated that CVE-2026-86950 is specifically used for stealing cryptocurrencies, and SlowMist has also not yet been publicly proven to be the exact vulnerability used in the previous wallet theft incidents that were under investigation.
Not long before this warning was issued, SlowMist had just investigated a malicious iOS application named FomoPeek. This application contained a kernel vulnerability exploit that allowed it to bypass Apple's app sandbox and access information belonging to other applications.
According to the investigation by SlowMist, the malicious version of FomoPeek is capable of obtaining higher levels of permission and may access information from Keychain as well as files stored by other applications.
It is alleged that the exploit framework for FomoPeek contains a variety of attack methods, is designed to target a wide range of iOS versions, and is intended to bypass Apple's normal sandbox restrictions.












