Security· ★★★· bearish·

Ledger CTO Warns of DarkSword iOS Exploit Stealing Crypto via Safari

  • DarkSword bypasses PAC and Safari's sandbox, then exploits the iOS kernel
  • The chain targets JavaScriptCore and harvests wallet data and keychains
  • Google disclosed six flaws, all fixed in iOS 26.3
  • Campaigns targeted users in Saudi Arabia, Turkey, Malaysia and Ukraine
Why it matters: iPhone users holding crypto should update iOS and keep seed phrases on a hardware wallet rather than in notes or cloud backups.
Source: U.Today