iOS Vulnerability Allows Theft of Keychain and Wallet Data via Link Click

A claim has emerged that an attack path enabling theft of keychain and wallet data following a link click has been constructed targeting iOS versions 13 through 26.5. SlowMist CISO 23pds asserted on X that attackers can extract private keys and seed phrases via links, explaining the process involves memory corruption in WebKit and JavaScript areas after Safari web access, followed by PAC bypass, native calls, WebContent sandbox escape, and kernel privilege escalation to retrieve keychain and wallet data. Apple's iOS 26.5 security documentation notes fixes for memory corruption, sandbox external access, and sensitive information exposure vulnerabilities related to WebKit, though the document does not confirm all aspects of 23pds' claimed attack path. SlowMist recommends iOS users update to the latest version.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: iOS 13~26.5, 링크 클릭 뒤 키체인·지갑 탈취 공격 주장