Apple Patches iOS Flaw That Could Let Attackers Run Malicious Code on iPhones
Apple has launched iOS 26.7.1 and iPadOS 26.7.1 on September twenty eighth with a safety repair for a critical vulnerability that would enable attackers to run arbitrary code on affected gadgets.
The tech big mentioned the difficulty includes an out-of-bounds write in CoreGraphics and added that the flaw may very well be triggered by processing a specifically crafted file.
SlowMist Warns Crypto Users
Apple confirmed that it might have been exploited in an “extraordinarily subtle assault” towards particular focused people on iOS variations earlier than iOS 27.
Meanwhile, SlowMist said the vulnerability is related to iOS assault exercise it has been monitoring. The safety agency additionally warned that crypto customers ought to pay specific consideration. It urged them to replace their Apple gadgets and keep away from suspicious hyperlinks, information, and app set up prompts. Users must also watch out when downloading apps or opening content material from unknown sources.
The vulnerability impacts a variety of Apple gadgets, together with iPhone 11 and later fashions, together with a number of current iPad fashions.
Malicious FomoPeek iOS App
Every week earlier, SlowMist had reported an iOS-related safety menace involving the FomoPeek app. The safety agency mentioned it obtained a number of studies of customers shedding digital property and located that affected customers had suffered non-public key publicity. Some had beforehand put in FomoPeek variations 1.1 and 1.2.
A joint investigation by SlowMist and OKX’s safety groups discovered malicious code contained in the app. According to the investigation, FomoPeek contained an iOS kernel exploitation framework with eight assault strategies. The framework might reportedly choose an exploit primarily based on the system mannequin and iOS model.
Affected variations included iOS 12.0-18.7 and iOS 26.0-26.1. If profitable, the exploit might escape the iOS sandbox and entry Keychain knowledge and information from different apps. This might expose non-public keys, seed phrases, login credentials, in addition to different delicate info. Hidden server connections have been additionally discovered that would obtain distant instructions, with the assault performance reportedly operating routinely at common intervals.
Earlier this yr, Apple was sued by three individuals for allegedly selling a faux model of the Sparrow Wallet crypto app by means of its App Store. The faux app reportedly drained a complete of $1.8 million from the victims’ wallets between May and August 2025.
The put up Apple Patches iOS Flaw That Could Let Attackers Run Malicious Code on iPhones appeared first on CryptoPotato.
