Apple fixes a serious iPhone vulnerability related to encryption attacks
U.Today
58m ago
Ai Focus
Apple has patched a serious iPhone vulnerability, and blockchain security company SlowMist warns that this vulnerability is particularly relevant to cryptocurrency users. Apple stated that the vulnerability may have been exploited in extremely complex attacks targeting specific individuals.
Helpful
No.Help

Apple has patched a serious iPhone vulnerability. Blockchain security company SlowMist warns that this vulnerability is particularly relevant to cryptocurrency users.

The vulnerability is identified as CVE-2026-86950 and affects Apple's CoreGraphics framework. After a device processes a maliciously constructed file, an attacker may be able to execute arbitrary code.

On September 28, Apple released iOS 26.7.1 and iPadOS 26.7.1 to fix this issue. The company stated that they had become aware of a report indicating that the vulnerability "may have been exploited in extremely complex attacks targeting specific individuals running versions of iOS prior to iOS 27."

Apple describes CVE-2026-86950 as a buffer overflow write vulnerability, which means that malicious data could cause the software to write information outside of the memory area allocated to it. Such memory corruption vulnerabilities could be exploited to make the device execute code controlled by the attacker.

Apple stated that the vulnerability was reported by Meta Product Security. The company fixed this issue by improving boundary checks.

Why Cryptocurrency Users May Face Risks

The blockchain security company SlowMist is paying attention to this update because of recent activities involving iOS that target cryptocurrency users.

SlowMist Apple has released an important iOS / iPadOS 26.7.1 security update, which fixes CVE-2026-86950, a buffer overflow write vulnerability that could potentially allow arbitrary code execution.

The company stated that this patch is "highly relevant" to the iOS attack activities they had previously tracked.

SlowMist warns, "This is particularly concerning for cryptocurrency users, as the iOS exploitation activities we have observed are targeting sensitive wallet data."

Importantly, Apple itself has not stated that CVE-2026-86950 is specifically used for stealing cryptocurrencies, and SlowMist has also not yet been publicly proven to be the exact vulnerability used in the previous wallet theft incidents that were under investigation.

Not long before this warning was issued, SlowMist had just investigated a malicious iOS application named FomoPeek. This application contained a kernel vulnerability exploit that allowed it to bypass Apple's app sandbox and access information belonging to other applications.

According to the investigation by SlowMist, the malicious version of FomoPeek is capable of obtaining higher levels of permission and may access information from Keychain as well as files stored by other applications.

It is alleged that the exploit framework for FomoPeek contains a variety of attack methods, is designed to target a wide range of iOS versions, and is intended to bypass Apple's normal sandbox restrictions.

Tip
$0
Like
0
Save
0
Views 14
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Geely Zhichong C12 takes the lead in being implemented in Hangzhou, Shanghai, Ningbo, Jiaxing, and Xi'an: Single-unit peak power of 2250 kilowatts, with an average charging time of 8 minutes and 40 seconds for 10% to 97% battery charge.
According to "NBD", Geely Smart Charging C12 has been launched simultaneously in five cities: Hangzhou, Shanghai, Ningbo, Jiaxing, and Xi'an. Geely states that the peak power of each charging station is 2.2 megawatts, and the average charging time for 10% to 97% battery recharge is 8 minutes and 40 seconds. It is also equipped with AI smart charging technology, battery temperature control, charging robots, as well as a plan for expanding the number of charging stations.
The Block
·2026-09-29 17:23:43
6
HCLTech Releases the First AI Synthetic Research Report Aimed at the Global Financial Management Industry
HCLTech releases its first AI synthetic research report titled " Hidden In Pl ( AI )n Sight ", based on profiles of 1,066 individuals from the wealth management industry across 17 markets. The report indicates that 84% of global wealth management companies believe there is a need to completely reshape their operational models, yet only slightly over 7% of these companies are actively developing agent-based AI capabilities.
PR Newswire
·2026-09-29 17:06:18
14
The White House blames Democrats after the Senate stops the advancement of "Crypto Clarity Act"
The White House blamed Democrats after the U.S. Senate vetoed the advancement of the "Crypto Clarity Act" bill with a vote of 49 to 50, stating that they placed partisan games above America's technological leadership. The White House's crypto advisor, Patrick Witt, called the result "very disappointing," while Democrats argued that the bill did not adequately address Trump's conflicts of interest in crypto and more stringent ethical rules.
Coinpedia
·2026-09-29 16:51:53
22
AI How does encrypted pre-sale work: Analysis of the AI agency launch model for MemeToro
AI Cryptocurrency presales are changing the path for early-stage projects from concept to public token issuance. MemeToro Taking Propose, Verify, Fund, and Launch on BNB Chain as examples, this article introduces their phased fundraising methods, smart contract rules, and the uses of the $MT tokens.
U.Today
·2026-09-29 16:51:51
23
Taiwan ORing Promotes the Development of Global Railway On-Board Connectivity
ORing Industrial Networking releases a new generation of IRoN railway Ethernet switch product portfolio on InnoTrans 2026. The company stated that its products have been applied in passenger and freight railway projects in Europe, the United States, and Asia. The new IRoN series offers configurations such as TSN, 10GbE, or PoE ++, and is moving forward to meet the IEC 62443-4-2 security level 2 requirements and related certifications.
PR Newswire
·2026-09-29 16:51:48
14
View More