慢雾:iOS Safari DarkSword攻击可窃取钱包输入,零点击触发六漏洞链
The Odaily Planet Daily reports that according to the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities code-named DarkSword, covering WebKit remote code execution, sandbox escape, and kernel read/write, allowing them to obtain app container files and keychain data without user awareness, as well as record keyboard inputs when wallets such as imToken, TokenPocket, or TronLink are in the foreground.
The SlowMist team stated that all six vulnerabilities mentioned above have now been patched by Apple, and the current attacks are a reuse of the n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen; confirmation still requires device forensics. It is recommended that iOS/iPadOS users upgrade their systems to 18.7.3 or 26.3 and above as soon as possible.
