- SlowMist said attackers are using the DarkSword exploit to target iPhone owners’ crypto wallets through malicious links opened in Safari.
- Successful exploitation could allow attackers to escape the browser sandbox, gain elevated privileges and access wallet data and private keys, according to SlowMist.
- SlowMist claimed DarkSword has been adapted for newer iOS versions, including iOS 26.5, but that claim has not been independently confirmed.
SlowMist has warned that attackers are using the DarkSword exploit to target crypto wallet owners on iPhones through Safari. The attack matters because successful exploitation could give attackers elevated access to a device and expose crypto wallet information and private keys, according to the firm.
SlowMist Chief Information Security Officer 23pds, who is known by that pseudonym, reported that attackers are distributing malicious links and prompting victims to open them in Safari.
According to 23pds, successful exploitation of the vulnerabilities can allow attackers to escape Safari’s browser sandbox, gain elevated privileges and access data stored on the device, including crypto wallet information and private keys.
Google Threat Intelligence Group previously investigated DarkSword and identified a chain of six vulnerabilities used in attacks against users in Saudi Arabia, Turkey, Malaysia and Ukraine. Google said the exploit supported iOS versions 18.4 through 18.7 and that the known vulnerabilities had been fixed with the release of iOS 26.3.
SlowMist now claims that attackers have adapted DarkSword to support newer versions of Apple’s operating system, including iOS 26.5. That information has not been independently confirmed.
Experts recommend that iPhone users install the latest available iOS version and avoid suspicious links received through social networks and messaging services.
In a separate case reported earlier, a crypto trader lost about $600,000 after encountering a fake Cloudflare verification.
Source: Incrypted
