Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, patching a critical out-of-bounds write vulnerability in CoreGraphics that could allow attackers to execute arbitrary code on affected devices. The company acknowledged the flaw may have been exploited in an extremely sophisticated attack against targeted individuals on iOS versions prior to iOS 27. SlowMist highlighted the particular risk for cryptocurrency users and urged immediate updates. A joint investigation by SlowMist and OKX revealed that the malicious FomoPeek app contained an iOS kernel exploitation framework with eight attack methods capable of stealing private keys, seed phrases, and credentials through Keychain access.
Source: Read the original article

