BTC $79,266.74 -0.59%
ETH $2,450.01 -0.29%
BNB $714.98 -0.56%
XRP $1.40 -0.71%
SOL $101.18 -1.40%
TRX $0.3289 -0.09%
DOGE $0.0848 +0.02%
ADA $0.2130 -0.26%
BCH $251.22 -0.73%
LINK $11.62 +0.20%
HYPE $84.46 +1.06%
AAVE $130.34 -0.94%
SUI $0.7492 -3.18%
XLM $0.1797 -0.57%
ZEC $983.15 +13.97%
BTC $79,266.74 -0.59%
ETH $2,450.01 -0.29%
BNB $714.98 -0.56%
XRP $1.40 -0.71%
SOL $101.18 -1.40%
TRX $0.3289 -0.09%
DOGE $0.0848 +0.02%
ADA $0.2130 -0.26%
BCH $251.22 -0.73%
LINK $11.62 +0.20%
HYPE $84.46 +1.06%
AAVE $130.34 -0.94%
SUI $0.7492 -3.18%
XLM $0.1797 -0.57%
ZEC $983.15 +13.97%

Slow Fog: iOS Safari DarkSword attack can steal wallet inputs, zero-click triggers six vulnerability chains

2026-09-04 20:10:49

According to the Slow Fog Security Team, they have detected an attack activity disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2.

The attackers exploited six vulnerabilities codenamed DarkSword to form a complete attack chain, covering aspects such as WebKit remote code execution, sandbox escape, and kernel read/write, allowing them to obtain App container files and keychain data without user awareness, and to record keyboard inputs when wallets like imToken, TokenPocket, or TronLink are in the foreground.

The Slow Fog team stated that the aforementioned six vulnerabilities have now been patched by Apple, and the current attack belongs to the reuse of n-day vulnerability chains. Simply visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen; confirmation still requires device forensics. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.

app_icon
ChainCatcher Building the Web3 world with innovations.