Crypto Prices

Investigation Uncovers Safari Vulnerability Threatening iPhone Crypto Security

2 hours ago
1 min read
2 views

Investigation into iPhone Security Threats

A recent investigation into potential security threats targeting iPhone users has revealed the reuse of known vulnerabilities in the Safari web browser, particularly affecting systems from iOS versions 18.4 to 18.6.2. SlowMist, a cybersecurity firm, communicated to Cointelegraph that while they have not verified any actual cryptocurrency theft linked to the Safari exploit, alarming reports have emerged. These reports caution iPhone users about malicious Safari pages that could compromise critical information such as crypto private keys and seed phrases, with affected systems suspected to range from iOS 13 through iOS 26.5.

Effectiveness of the Exploit

Currently, the effectiveness of the exploit on later versions, including iOS 26.5, remains uncertain. Despite the broader range identified, SlowMist has treated the latter version as tentative due to a lack of conclusive technical evidence. The firm stressed the need for additional scrutiny before confirming if iOS 26.5 is indeed under threat from this exploit.

Methods and Campaigns

The methods underpinning this Safari attack mirror techniques from the recently publicized DarkSword exploit, made known in March by Google’s Threat Intelligence Group (GTIG), which has been associated with several threat actors since November 2025. Remarkably, the activity was first recognized by SlowMist’s threat intelligence team, MistEye, in early May this year.

On September 4, SlowMist published findings concerning a particular campaign they named WYINCC, pinpointing a malicious webpage that promised free virtual private server services. Upon access via Safari on an iPhone, this page automatically executed exploit code without user interaction. Though Apple has previously patched the vulnerabilities exploited in this attack, SlowMist’s analysis revealed that the malicious Safari sample collected information from Apple’s Keychain and could potentially expose data associated with crypto wallet applications.

Recommendations for Users

SlowMist explained that while the exploit sample demonstrated the capacity to collect sensitive information, it did not provide proof of successful data extraction from every targeted wallet. They conveyed that without executing the full attack chain on a live victim device, they couldn’t confirm any specific individual had fallen victim to the discovered exploit.

Given the ongoing risks posed by this type of attack, SlowMist recommends that iPhone users update their devices with the latest iOS security patches and exercise caution when navigating links, especially those that seem dubious. For users unable to update immediately or who find themselves at heightened risk, the firm suggested enabling Apple’s Lockdown Mode for added protection, although they did not confirm its efficacy against this specific threat. SlowMist also advised taking precautionary measures such as transferring any potentially exposed crypto assets to a new wallet on a secure device.

Conclusion

In light of these developments, cryptocurrency stakeholders and casual users alike are urged to remain vigilant as the implications of these vulnerabilities continue to unfold.

Popular