Apple has released iOS 26.7.1 and iPadOS 26.7.1 on September 28th with a security fix for a serious vulnerability that could allow attackers to run arbitrary code on affected devices.
The tech giant said the issue involves an out-of-bounds write in CoreGraphics and added that the flaw could be triggered by processing a specially crafted file.
SlowMist Warns Crypto Users
Apple confirmed that it may have been exploited in an “extremely sophisticated attack” against specific targeted individuals on iOS versions before iOS 27.
Meanwhile, SlowMist said the vulnerability is relevant to iOS attack activity it has been tracking. The security firm also warned that crypto users should pay particular attention. It urged them to update their Apple devices and avoid suspicious links, files, and app installation prompts. Users should also be careful when downloading apps or opening content from unknown sources.
The vulnerability affects a range of Apple devices, including iPhone 11 and later models, along with several recent iPad models.
Malicious FomoPeek iOS App
A week earlier, SlowMist had reported an iOS-related security threat involving the FomoPeek app. The security firm said it received multiple reports of users losing digital assets and found that affected users had suffered private key exposure. Some had previously installed FomoPeek versions 1.1 and 1.2.
A joint investigation by SlowMist and OKX’s security teams found malicious code inside the app. According to the investigation, FomoPeek contained an iOS kernel exploitation framework with eight attack methods. The framework could reportedly select an exploit based on the device model and iOS version.
Affected versions included iOS 12.0-18.7 and iOS 26.0-26.1. If successful, the exploit could escape the iOS sandbox and access Keychain data and files from other apps. This could expose private keys, seed phrases, login credentials, as well as other sensitive information. Hidden server connections were also found that could receive remote commands, with the attack functionality reportedly running automatically at regular intervals.
Earlier this year, Apple was sued by three people for allegedly promoting a fake version of the Sparrow Wallet crypto app through its App Store. The fake app reportedly drained a total of $1.8 million from the victims’ wallets between May and August 2025.
The post Apple Patches iOS Flaw That Could Let Attackers Run Malicious Code on iPhones appeared first on CryptoPotato.

Comments (0)
Please sign in to comment.
No comments yet. Be the first to comment.