Security· ★★★★· bearish·

SlowMist: Hackers Deploy Full Attack Chain on iOS Users via Safari

  • The attack begins with a link click to steal private keys and seed phrases
  • Through WebKit/JSC, hackers gain JS access, bypass PAC, and escape the WebContent sandbox
  • After a kernel exploit with root privileges, Keychain and wallet data are stolen
  • iOS 13–26.5 are vulnerable; immediate update is recommended
Why it matters: iOS users with crypto wallets face the risk of key theft when clicking a link in Safari — an urgent system update is needed.
Source: PANews