SlowMist: Black/gray market actors have achieved a full attack chain against iOS users, affecting iOS 13 through 26.5
PANews reported on September 19 that SlowMist Chief Information Security Officer 23pds posted on X that black/gray market actors have achieved an attack chain against iOS users: clicking a link extracts private keys and mnemonic phrases; when users visit a webpage with Safari, memory corruption in WebKit/JSC is used to gain read/write capability at the JS layer; PAC is bypassed to gain native call capability; the WebContent sandbox is escaped; and kernel privilege escalation obtains root access to exfiltrate Keychain and wallet data. Affected versions are iOS 13 through 26.5, and iOS users are advised to upgrade as soon as possible.
Source: PANews