SlowMist founder Yu Xian said a food delivery app called ComeCome, available at comecome.icu, was found using attack methods similar to those seen in the earlier FomoPeek App poisoning and crypto theft incident. According to ChainCatcher, the FomoPeek v1.1-1.2 versions contained a malicious SDK and integrated eight iOS kernel exploit methods that could automatically choose an attack path based on device model and system version.
The affected iOS versions are known to include iOS 12-18.7 and 26-26.1. If the attack succeeds, it can bypass the iOS sandbox and steal assets from crypto wallets.
Yu Xian said the threat may also affect iPad and Mac devices. He advised users to update to the latest iOS version immediately and remain highly cautious of apps from unknown sources.