Safari Zero-Day Exploit Targets iPhone Crypto Wallets
A critical vulnerability has been discovered in Apple's mobile ecosystem, targeting iPhones running iOS 13 through 26.5 and crypto wallets.
The exploit, confirmed by blockchain security firm SlowMist, uses a memory corruption flaw in WebKit to steal private keys and mnemonic seed phrases from crypto wallets.
The attack chain begins with a malicious Safari webpage that bypasses Apple's built-in mechanism for verifying software instructions, Pointer Authentication Codes. It then breaks out of the browser's sandbox and escalates all the way to kernel-level access.
With kernel access, an attacker can reach the iOS Keychain, where sensitive credentials are stored. This means private keys and seed phrases can be quietly copied off a device without the owner ever knowing.