Slow Fog: iOS Safari DarkSword Attack Steals Wallet Inputs, Six Vulnerabilities Exploited
The Slow Fog security team has detected an attack targeting the iPhone Safari browser versions 18.4 to 18.6.2. Attackers have formed a complete attack chain using six vulnerabilities codenamed DarkSword, covering aspects such as WebKit remote code execution, sandbox escape, and kernel read/write. This allows them to obtain App container files and keychain data without user awareness, and to record keyboard inputs when wallets like imToken, TokenPocket, or TronLink are in the foreground. The Slow Fog team stated that these six vulnerabilities have been patched by Apple, and the current attack is a reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen; confirmation still requires device forensics. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Can Bitcoin Be Bought with Rp50,000? Here's How - Fintech World

Anthropic: The Report That Implicates Claude, Between Missiles, Espionage in Mali, and Chinese Pillaging

Pump.fun Mobile App Temporarily Removed from App Store in the US and India

Ongoing Phishing After Brevo Hack

Diesel Drives PPI Up by One-Third, Why Rate Cuts Are Further Away

Strategy erased nearly $8 billion of net debt in 11 months and put S&P’s junk rating on the clock

US Clarity Bill: Senator Cynthia Lummis Publishes Revised Version Before Vote

Valinor Launches Tokenized BDC Fund VBDC on Superstate FundOS

US Dollar Stagnates, Inflation and Interest Rates in Focus

MoneyGram Launches First Stablecoin Visa Card in Colombia, Supporting USDC

Don't Just Focus on the Fed! Coin Metrics Reveals the Real 'Turning Point Code' for Bitcoin: Non-Farm Payrolls Have the Biggest Impact, Core CPI is More Persistent

Coinbase expands AI access to stocks and crypto

Coinbase CEO predicts Bitcoin bottom reached, uptrend in 1-2 years

Activation of Solana Beta Mainnet Transaction V1 Delayed to Epoch 1035

Arab Airline Cancels Flights to Russia Following Zelensky's Warning

Flop Labs Launches KOL Ranking Program

Cardano founder weighs OpenAI’s math breakthrough

大冰要抄底(专注交易) Highlights Critical Point in U.S. Economic Data

ChatGPT, Claude, and Grok All Go Down: Why Is Everyone Suspecting Cloudflare?

Hackers Stole $320 Million Worth of BTC but Returned Most of It!

Bitcoin Mining Electricity Cost of $5.68: The Pitfall of 2010 Calculations

Operation NABU "Carthage": What Business Thinks About the New Corruption Scandal

White House Advisor Predicts Skepticism Around CLARITY Act Will Soon Be Proven Wrong

MSCI Emerging Markets Stock Index Rises to Two-Month High, Tech Stocks Perform Best

American Crypto Bill Faces Years of Delay, Vote on September 15

LeBron James Partners with Polymarket, First NBA Player to Do So

XRP Ledger fixCleanup3_3_0 Proposal Awaits Activation on September 11

Crypto: Essential Tips for Developers to Protect Their Computers and Wallets

AI Data Centers: Cooling Goes Under the Sea





