Apple has issued emergency security updates for iOS 26.7.1 and iPadOS 26.7.1 on September 28th to patch a critical vulnerability that allows attackers to execute arbitrary code on affected devices.
CoreGraphics Vulnerability and Active Exploits
Apple confirmed that the issue involves an out-of-bounds write flaw in CoreGraphics triggered by processing a specially crafted file. The tech giant acknowledged that the security flaw may have been leveraged in an "extremely sophisticated attack" against specific targeted individuals running operating system versions prior to iOS 27. The vulnerability impacts iPhone 11 and later models, alongside several recent iPad iterations.
Blockchain security firm SlowMist warned cryptocurrency holders that the vulnerability aligns with active iOS attack vectors it has been tracking. The firm advised users to update their devices immediately and refrain from opening suspicious links, downloading files, or accepting unexpected application installation prompts from unknown sources.
Malicious FomoPeek App Extracts Seed Phrases
The security release follows SlowMist's disclosure one week prior regarding a malicious iOS application called FomoPeek. A joint investigation by SlowMist and OKX's security teams revealed that FomoPeek versions 1.1 and 1.2 contained an iOS kernel exploitation framework equipped with eight attack methods targeting iOS 12.0 through 18.7 and iOS 26.0 through 26.1.
Upon execution, the framework escaped the iOS sandbox to access Keychain data and third-party app files, directly exposing private keys, seed phrases, and login credentials. The malicious code also maintained hidden server connections to execute remote commands automatically at scheduled intervals. Smartphone safety remains critical across the ecosystem, particularly as users face diverse operational risks like when Zano rolled back one month of blockchain transactions following a gateway exploit. Apple itself was sued earlier this year by three victims after a fake Sparrow Wallet app on the official App Store drained $1.8 million from user wallets between May and August 2025.
Key Takeaways
- Emergency Patch: Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28th to fix an out-of-bounds write in CoreGraphics.
- Targeted Exploitation: Apple acknowledged the vulnerability was used in targeted exploits against systems preceding iOS 27.
- Credential Theft: Malicious app FomoPeek (versions 1.1 and 1.2) used eight attack methods to break sandbox protections and steal Keychain seed phrases.
- App Store Risks: Apple faces legal action after a fake Sparrow Wallet app drained $1.8 million from users in mid-2025.
Why It Matters
Because mobile smartphones function as the primary hardware wallet interface for millions of retail and institutional crypto investors, zero-day operating system exploits present an immediate threat to asset security. Sandbox-escaping vulnerabilities undermine the fundamental assumption that device Keychain storage isolates private keys from malicious software. Traders must treat OS updates as critical defensive measures, as attacker techniques increasingly shift toward silent, automated credential extraction.



