Wednesday, 30 September 2026
BTC $82,965 −1.24% ETH $2,663 −1.86% SOL $118.11 −1.16% XRP $1.49 −0.97% BNB $757.41 −1.12% DOGE $0.093 −2.06% ADA $0.243 −3.87% TON $1.47 −7.55% AVAX $11.11 −2.82% BTC $82,965 −1.24% ETH $2,663 −1.86% SOL $118.11 −1.16% XRP $1.49 −0.97% BNB $757.41 −1.12% DOGE $0.093 −2.06% ADA $0.243 −3.87% TON $1.47 −7.55% AVAX $11.11 −2.82%
GPreferred sourceon Google
Advertise
Latest
Security

Apple Patches iOS Flaw Tied to Crypto Attacks

Hands holding an iPhone displaying a software update screen, representing Apple's iOS security patch.

Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, patching a CoreGraphics vulnerability that the company said may have been exploited in an “extremely sophisticated attack” against specific targeted individuals, according to a report by Cryptopotato.

Apple has fixed CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics that could allow arbitrary code execution on iPhones and iPads. The patch, released on September 28, addresses a vulnerability that may have been used in highly targeted attacks. SlowMist warns crypto users to update immediately and avoid suspicious links, files, and app installation prompts.

SlowMist ties patch to ongoing iOS exploitation

Blockchain security firm SlowMist said the update is “highly relevant” to the iOS attack activity it has previously investigated. “For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data,” the firm said, as reported by both U.Today and Cryptopotato.

U.Today reported that the vulnerability was reported by Meta Product Security and was fixed with improved bounds checking. Apple has not said that CVE-2026-86950 was specifically used to steal cryptocurrency, and SlowMist has not publicly established that the newly disclosed flaw was the exact exploit used in previously investigated wallet thefts. That distinction matters: the connection between the patch and crypto losses remains circumstantial, even as the security firm urges caution.

FomoPeek malware raised alarms a week earlier

The warning comes a week after SlowMist reported on FomoPeek, a malicious iOS app that contained a kernel exploitation framework with eight attack methods. According to a joint investigation by SlowMist and OKX’s security teams, the framework could select an exploit based on the device model and iOS version. Affected versions included iOS 12.0–18.7 and iOS 26.0–26.1.

If successful, the exploit could escape the iOS sandbox and access Keychain data and files from other apps, potentially exposing private keys, seed phrases, and login credentials. SlowMist said some users who lost digital assets had installed FomoPeek versions 1.1 and 1.2. Hidden server connections capable of receiving remote commands were also found, with the attack functionality reportedly running automatically at regular intervals.

Why it matters

For crypto holders, the iPhone is often the primary device for managing wallets, authenticating exchanges, and storing recovery phrases. A flaw that enables sandbox escape or unauthorized data access can translate directly into stolen funds, especially when users install apps from outside the App Store or open files from unknown sources. The timing of the patch — just days after the FomoPeek disclosure — underscores how quickly iOS vulnerabilities can be weaponized against crypto users.

The episode also highlights the limits of platform security. Apple’s App Store review has been challenged before: earlier this year, three people sued Apple for allegedly promoting a fake version of the Sparrow Wallet crypto app that drained $1.8 million from victims’ wallets between May and August 2025. While that case is separate from CVE-2026-86950, it reinforces that users cannot rely solely on platform gatekeeping to protect digital assets.

What to watch

Apple has not disclosed further details about the “extremely sophisticated attack,” and it is unclear whether the flaw was used in any confirmed crypto theft. SlowMist’s ongoing tracking of iOS exploitation activity will be the key indicator of whether this vulnerability becomes a broader threat to wallet security. Users should install iOS 26.7.1 or iPadOS 26.7.1 immediately and monitor official channels for any additional guidance.

Frequently Asked Questions

What is CVE-2026-86950?

It is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework that could let attackers run malicious code on affected iPhones and iPads by processing a specially crafted file.

Which devices are affected by the iOS flaw?

The vulnerability impacts iPhone 11 and later models, as well as several recent iPad models, according to Apple.

Why are crypto users specifically warned?

SlowMist says the flaw is relevant to recent iOS attack activity targeting sensitive wallet data, and urges crypto users to update their devices and avoid suspicious apps, links, and files.

What is the FomoPeek app?

FomoPeek is a malicious iOS app that SlowMist and OKX found contained a kernel exploitation framework with eight attack methods, capable of accessing private keys and other sensitive data.

Sources: CryptoPotato, U.Today

Not investment adviceBitcoinWorld publishes news and analysis for information only. Nothing here is a recommendation to buy, sell or hold any asset. Digital assets are volatile and you can lose your entire capital. Consider your own circumstances and speak to a regulated adviser before acting. Read the full disclaimer.

Keshav Aggarwal

Co-Founder & Responsible Editor

Keshav Aggarwal is the Co-Founder & CEO of BitcoinWorld, a Google News - indexed publication covering crypto, AI, and forex markets since 2020. A blockchain investor and trader with over six years in the digital-asset space, he built one of India's most active crypto investor communities and has guided thousands of retail participants through their first investments in the asset class. At BitcoinWorld, he sets editorial direction across the newsroom and reports on the business of crypto, AI, and Web3 - tracking the funding rounds, product launches, and regulatory shifts shaping the future of finance and frontier technology.

Spotted an error in this article? We correct openly and log every change.Report a correction

More in Security

See all →