iOS Exploit Steals Crypto Wallet Keys with Single Click
SlowMist CISO 23pds issued an urgent warning on September 19 about a full-chain iOS exploit that can silently drain private keys and mnemonic seed phrases from crypto wallets. The attack affects devices running iOS 13 through iOS 26.5, making it a serious threat to self-custodied assets held in mobile wallets.
The exploit chain works by exploiting a memory-corruption bug in WebKit and JavaScriptCore when a target visits a malicious webpage in Safari. This allows the attackers to gain arbitrary read and write access at the JavaScript layer, bypassing Pointer Authentication Codes to execute native code and escalate to kernel-level root privileges.
Unlike conventional phishing attacks that trick users into typing their seed phrases, this exploit requires no action beyond visiting a link, making it particularly urgent. The affected range runs from iOS 13 through iOS 26.5, with the upper bound still pending final confirmation.