Apple Patches Critical iPhone Flaw Tied to Crypto Attacks

CVE-2026-86950SlowMist
1 hour agoSource: u.today
Apple Patches Critical iPhone Flaw Tied to Crypto Attacks

Apple has patched a serious iPhone vulnerability that may have already been exploited in highly sophisticated attacks, with blockchain security firm SlowMist warning that the flaw is particularly relevant to cryptocurrency users.

The vulnerability, tracked as CVE-2026-86950, affects Apple’s CoreGraphics framework and could allow attackers to execute arbitrary code after a device processes a maliciously crafted file.

Apple addressed the issue with the release of iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28. The company said it was aware of a report indicating that the vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals” running versions of iOS released before iOS 27.

Apple described CVE-2026-86950 as an out-of-bounds write vulnerability, meaning malicious data could cause software to write information outside the memory area allocated to it. Such memory-corruption bugs can potentially be leveraged to make a device execute attacker-controlled code.

The vulnerability was reported by Meta Product Security, according to Apple. The company fixed it by introducing improved bounds checking.

Why crypto users could be at risk

Blockchain security firm SlowMist has drawn attention to the update because of recent iOS exploitation activity involving cryptocurrency users.

"Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution," SlowMist said.

The firm said the patch was "highly relevant" to the iOS attack activity it had previously been tracking.

"For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data," SlowMist warned.

Importantly, Apple itself has not said that CVE-2026-86950 was specifically used to steal cryptocurrency, nor has SlowMist publicly established that the newly disclosed vulnerability was the exact exploit used in previously investigated wallet thefts. 

That warning comes shortly after SlowMist investigated a malicious iOS application called FomoPeek that contained kernel exploits capable of escaping Apple's application sandbox and accessing information belonging to other apps.

According to SlowMist's investigation, malicious versions of FomoPeek were capable of obtaining elevated privileges and potentially accessing Keychain information and files stored by other applications. 

The FomoPeek exploit framework reportedly contained multiple attack methods targeting a wide range of iOS releases and was designed to bypass Apple's normal sandbox restrictions.