SlowMist: Darksword vulnerability reportedly exploits iOS 26.5 to steal private keys
SlowMist CISO 23pds reported that attackers are leveraging the Darksword vulnerability to bypass iOS security via Safari, potentially gaining root access to extract private keys from self-custodial wallets. While Google Threat Intelligence Group previously identified the exploit affecting iOS 18.4 through 18.7, 23pds claims it has been adapted for iOS 26.5, though this remains unverified. Attacks typically begin with social engineering via malicious links. Separately, three investors have filed a lawsuit against Apple after losing nearly $1.8 million in Bitcoin due to fake wallet applications downloaded from the official App Store.
Summaries are written by AI from the original article. Not investment advice.