A newly reported iPhone security vulnerability can expose users’ cryptocurrencies: cybersecurity experts warn of an exploit chain capable of stealing sensitive data, such as private keys and recovery phrases, without users noticing. The attack is initiated through social engineering that prompts victims to open a malicious page in Safari, which then exploits a flaw in WebKit/JavaScriptCore to gain unauthorized access to data.
iPhone Security: How the Exploit Works
Experts say the exploit chain begins with a social engineering procedure that convinces a user to load a crafted webpage in Safari. That page leverages a WebKit/JavaScriptCore vulnerability to bypass protections and extract information, potentially reaching data stored in the iOS keychain and in cryptocurrency wallet applications.
Who Is Affected and How to Protect Yourself
According to the report, iPhone versions running iOS 13 through iOS 26.5 may be affected, although the full scope of impacted versions has not been confirmed. To reduce risk, users are advised to update their devices when patches are available and to avoid opening untrusted links in Safari—especially if private wallet keys or recovery phrases are stored on the phone.
This content is provided for general informational purposes only and doesn’t constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

