Apple has resolved a critical vulnerability in its iPhone CoreGraphics framework with a new security update, following warnings that the flaw may have already been exploited in targeted attac
Apple has resolved a critical vulnerability in its iPhone CoreGraphics framework with a new security update, following warnings that the flaw may have already been exploited in targeted attacks. Blockchain security firm SlowMist stated that the vulnerability poses a particular risk to cryptocurrency users.
Details of the vulnerability
Tracked as CVE-2026-86950, the vulnerability resides in Apple’s CoreGraphics framework. Experts described it as an out-of-bounds write bug, which allows malicious data to force the affected device to write information outside designated memory limits. This form of memory corruption can potentially give an attacker the ability to run arbitrary code on the device.
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28 to address the issue. The company noted that it received information suggesting the flaw had possibly been exploited in highly sophisticated attacks against specifically targeted individuals using earlier iOS versions.
Meta Product Security identified and reported the vulnerability, which Apple fixed by adding improved bounds checking to CoreGraphics.
Heightened risks for crypto users
Blockchain security firm SlowMist emphasized that this security update is especially relevant given the recent increase in iOS exploitation targeting cryptocurrency users.
SlowMist warned that recent exploitation activity on iOS has focused on sensitive wallet data, cautioning crypto users to take the update seriously.
The firm added that this patch is connected to incidents it had previously monitored in which attackers attempted to access sensitive information through vulnerabilities in Apple’s software.
Although SlowMist highlighted the risks to cryptocurrency holders, neither Apple nor SlowMist have confirmed that CVE-2026-86950 was directly used to steal cryptocurrency funds. There is also currently no public evidence establishing that the vulnerability was linked to any specific wallet thefts.
Recent iOS attacks and ongoing threats
The warning arrives shortly after SlowMist investigated a harmful iOS application called FomoPeek. According to the firm, this app included kernel exploits with the capability of breaking out of Apple’s sandbox, which normally isolates apps for security.
SlowMist found that malicious versions of FomoPeek could gain elevated privileges on the device, making it possible to access Keychain credentials and files belonging to other applications. The FomoPeek exploit framework reportedly included several attack vectors targeting a broad span of iOS releases and was purpose-built to bypass standard sandbox security measures.
With mobile devices handling a large portion of cryptocurrency activity, these developments underline the importance of immediate security updates and improved monitoring of app permissions. In a market where a single Fed decision or a sudden altcoin listing can change everything in seconds, jumping between different apps for charts, news, and portfolio tracking is costing investors money. Smart traders are now utilizing privacy-first tools like CryptoAppsy to consolidate everything. Without even the hassle of creating an account, you get real-time charts, smart price alerts, coin-specific news, and critical macro data all on one screen.
The post Apple patches iPhone security flaw with urgent update, SlowMist warns crypto users appeared first on COINTURK NEWS.