SlowMist Security Team said it detected an attack campaign disguised as a free VPS service that targets iPhone Safari browsers running iOS 18.4 to 18.6.2. According to Odaily, the attackers used six vulnerabilities codenamed DarkSword to build a full attack chain covering WebKit remote code execution, sandbox escape, and kernel read and write access.
The team said the attack can obtain App container files and keychain data without the user noticing, and can record keystrokes when wallets such as imToken, TokenPocket, or TronLink are in the foreground. SlowMist said Apple has already patched all six vulnerabilities, and the current campaign is a reuse of an n-day exploit chain.
SlowMist added that visiting a malicious page alone does not prove that a mnemonic phrase or private key has been stolen, and device forensics are still needed for confirmation. It advised iOS and iPadOS users to update to version 18.7.3 or 26.3 and later as soon as possible.