SlowMist: iOS Safari DarkSword Attack Can Steal Wallet Inputs, Zero-Click Trigger with Six-Vulnerability Chain
Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.
The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.
