Blockchain security firm SlowMist confirmed on September 19 that an active zero-day exploit in Safari can silently steal private keys and seed phrases from crypto wallets on iPhones running iOS 13 through 26.5. The attack starts with a malicious webpage exploiting a memory corruption flaw in WebKit and JavaScriptCore, then escalates to kernel-level access to reach the iOS Keychain where crypto credentials are stored. Ledger CTO Charles Guillemet amplified the warning on September 21, urging users to update iOS immediately and avoid clicking unfamiliar links. In case of suspected exposure, security researchers recommend treating the device as compromised and regenerating all keys on a clean device.
Source: Read the original article

