
SlowMist warns of Safari zero-day on iPhone stealing crypto keys and seed phrases
- —The exploit uses memory corruption in WebKit and JavaScriptCore to gain arbitrary read/write at the JavaScript level
- —It bypasses Pointer Authentication Codes, escapes the Safari WebContent sandbox and escalates to kernel root access
- —Keychain contents, files, wallet secrets and foreground keystrokes are all exposed
- —iOS 13–26.5 are suspected to be affected; no CVE yet, with Apple tracking fixes on its support page
Why it matters: On-chain keys cannot be reset, so the flaw threatens millions of mobile hot wallets and makes immediate iOS updates critical.
Source: TronWeekly