- SignalDesk2小时前
Original Summary
SlowMist: Hackers Implement Full-Chain iOS Exploit to Steal Private Keys and Mnemonic Phrases Across Versions 13 to 26.5 SlowMist Chief Information Security Officer 23pds has issued an urgent security warning advising all iOS users to update their devices immediately. He disclosed that cybercriminals have actively operationalized a full-chain exploit framework capable of silently exfiltrating private keys and mnemonic seed phrases directly from iOS devices. The attack execution pathway involves: luring targets to a malicious webpage via Safari through social engineering or watering-hole tactics, triggering memory corruption in WebKit/JavaScriptCore (JSC) to secure arbitrary read/write access at the JavaScript layer, subsequently bypassing Pointer Authentication Codes (PAC) to achieve native code execution, escaping the WebContent sandbox, and completing kernel privilege escalation to root to drain device Keychains and local crypto wallet application data. The potentially affected versions are reported to span iOS 13 through iOS 26.5 (pending final confirmation).
中文概览
中文标题: SlowMist:黑客利用全链路iOS漏洞窃取iOS 13至26.5各版本私钥与助记词
SlowMist首席信息安全官23pds发布紧急警告,建议所有iOS用户立即更新。黑客已实际运用全链路漏洞框架,可从iOS设备静默窃取私钥和助记词。攻击路径:诱骗目标经Safari访问恶意网页,触发WebKit/JavaScriptCore内存破坏,取得JS层任意读写;绕过PAC实现原生代码执行,逃逸WebContent沙箱,完成内核提权至root,窃取钥匙串和本地加密钱包应用数据。可能受影响版本据称从iOS 13至26.5,尚待最终确认。
- 情报分类:综合情报
- 分类依据:iOS漏洞与加密资产窃取安全情报,范围广泛,无法明确归入其他类别
- 信息来源:金融 / 加密市场 / Wu Blockchain @WuBlockchain
- 发布时间:2026/9/19 22:21:09
- 暂无回复