市值 —24小时交易量 —BTC —恐惧指数 —
大师投资投资 & 收益
广告
广告

苹果修复了可能让攻击者在iPhone上运行恶意代码的iOS漏洞

阅读310分享打印版
Apple Patches iOS Flaw That Could Let Attackers Run Malicious Code on iPhones

Apple has released iOS 26.7.1 and iPadOS 26.7.1 on September 28th with a security fix for a serious vulnerability that could allow attackers to run arbitrary code on affected devices.

The tech giant said the issue involves an out-of-bounds write in CoreGraphics and added that the flaw could be triggered by processing a specially crafted file.

SlowMist Warns Crypto Users

Apple confirmed that it may have been exploited in an “extremely sophisticated attack” against specific targeted individuals on iOS versions before iOS 27.

Meanwhile, SlowMist said the vulnerability is relevant to iOS attack activity it has been tracking. The security firm also warned that crypto users should pay particular attention. It urged them to update their Apple devices and avoid suspicious links, files, and app installation prompts. Users should also be careful when downloading apps or opening content from unknown sources.

The vulnerability affects a range of Apple devices, including iPhone 11 and later models, along with several recent iPad models.

Malicious FomoPeek iOS App

A week earlier, SlowMist had reported an iOS-related security threat involving the FomoPeek app. The security firm said it received multiple reports of users losing digital assets and found that affected users had suffered private key exposure. Some had previously installed FomoPeek versions 1.1 and 1.2.

A joint investigation by SlowMist and OKX’s security teams found malicious code inside the app. According to the investigation, FomoPeek contained an iOS kernel exploitation framework with eight attack methods. The framework could reportedly select an exploit based on the device model and iOS version.

Affected versions included iOS 12.0-18.7 and iOS 26.0-26.1. If successful, the exploit could escape the iOS sandbox and access Keychain data and files from other apps. This could expose private keys, seed phrases, login credentials, as well as other sensitive information. Hidden server connections were also found that could receive remote commands, with the attack functionality reportedly running automatically at regular intervals.

Earlier this year, Apple was sued by three people for allegedly promoting a fake version of the Sparrow Wallet crypto app through its App Store. The fake app reportedly drained a total of $1.8 million from the victims’ wallets between May and August 2025.

Source: CryptoPotato

更多关于主题 «Cryptocurrency News»

所有帖子
关于金钱的随机引用
Всякий расточитель – враг общества, всякий бережливый человек – благодетель.
— Адам Смит

其他部分的有趣内容

整个博客

评论 0

尚无评论

成为第一个分享您对此主题的看法或经验的人。

广告