Apple has launched iOS 26.7.1 and iPadOS 26.7.1 on September twenty eighth with a safety repair for a severe vulnerability that might enable attackers to run arbitrary code on affected units.
The tech large mentioned the difficulty includes an out-of-bounds write in CoreGraphics and added that the flaw could possibly be triggered by processing a specifically crafted file.
SlowMist Warns Crypto Customers
Apple confirmed that it might have been exploited in an “extraordinarily refined assault” in opposition to particular focused people on iOS variations earlier than iOS 27.
In the meantime, SlowMist mentioned the vulnerability is related to iOS assault exercise it has been monitoring. The safety agency additionally warned that crypto customers ought to pay specific consideration. It urged them to replace their Apple units and keep away from suspicious hyperlinks, recordsdata, and app set up prompts. Customers also needs to watch out when downloading apps or opening content material from unknown sources.
The vulnerability impacts a spread of Apple units, together with iPhone 11 and later fashions, together with a number of current iPad fashions.
Malicious FomoPeek iOS App
Per week earlier, SlowMist had reported an iOS-related safety menace involving the FomoPeek app. The safety agency mentioned it obtained a number of studies of customers dropping digital belongings and located that affected customers had suffered non-public key publicity. Some had beforehand put in FomoPeek variations 1.1 and 1.2.
A joint investigation by SlowMist and OKX’s safety groups discovered malicious code contained in the app. Based on the investigation, FomoPeek contained an iOS kernel exploitation framework with eight assault strategies. The framework may reportedly choose an exploit primarily based on the machine mannequin and iOS model.
Affected variations included iOS 12.0-18.7 and iOS 26.0-26.1. If profitable, the exploit may escape the iOS sandbox and entry Keychain information and recordsdata from different apps. This might expose non-public keys, seed phrases, login credentials, in addition to different delicate data. Hidden server connections have been additionally discovered that might obtain distant instructions, with the assault performance reportedly operating routinely at common intervals.
Earlier this yr, Apple was sued by three individuals for allegedly selling a faux model of the Sparrow Pockets crypto app by way of its App Retailer. The faux app reportedly drained a complete of $1.8 million from the victims’ wallets between Might and August 2025.
The submit Apple Patches iOS Flaw That Might Let Attackers Run Malicious Code on iPhones appeared first on CryptoPotato.