Apple patches iPhone flaw that SlowMist flags for crypto wallet risk
Apple released iOS 26.7.1 to fix CVE-2026-86950, a CoreGraphics bug that SlowMist links to iOS attack activity against crypto users.
Key takeaways
- Sept. 28 update. Apple shipped iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28 to close CVE-2026-86950.
- Eight attack methods. SlowMist found a FomoPeek framework with eight attack methods covering iOS 12.0-18.7 and iOS 26.0-26.1.
- Wallet losses reported. A fake Sparrow Wallet app reportedly drained $1.8 million from victims' wallets between May and August 2025.
What happened
Apple released iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28 to fix a flaw in its CoreGraphics framework. The bug is tracked as CVE-2026-86950. Apple classed it as an out-of-bounds write, which means malformed data can push software to write past the memory set aside for it. A specially crafted file can trigger the issue, and the result can be attacker-controlled code running on the device.
Apple said it knew of a report that the flaw may have been exploited in an extremely sophisticated attack on specific targeted individuals who ran iOS versions released before iOS 27. Meta Product Security reported the bug, and Apple fixed it by adding better bounds checking.
Blockchain security firm SlowMist drew attention to the update. It called the patch highly relevant to iOS attack activity it had been tracking, and said the issue is especially concerning for crypto users because of activity aimed at sensitive wallet data.
Why it matters
Phones hold wallet keys, seed phrases and login credentials for many crypto users, so a flaw that lets code run on a device matters beyond a normal patch cycle. SlowMist urged users to update Apple devices and to avoid suspicious links, files and app installation prompts.
The vulnerability covers a wide device range. It affects iPhone 11 and later models plus several recent iPad models, so a large group of users may need to update.
What the data shows
SlowMist's earlier look at FomoPeek turned up an iOS kernel exploitation framework that carried eight attack methods. The versions in scope were iOS 12.0-18.7 and iOS 26.0-26.1, and the framework could pick an exploit based on the device model and iOS build.
Losses have already been reported in a separate case. A fake Sparrow Wallet crypto app on Apple's App Store reportedly drained $1.8 million from victims' wallets between May and August 2025, and three people have sued Apple over it.
Background
SlowMist's FomoPeek investigation predates this week's update. The firm said the app carried kernel exploits that could break out of Apple's app sandbox and reach data held by other apps.
SlowMist said it received several reports of users losing digital assets and found private key exposure among affected users. Some of them had installed FomoPeek versions 1.1 and 1.2, and a joint investigation with OKX's security teams found malicious code inside the app.
What is still unclear
- Apple has not said the flaw was used to steal cryptocurrency, and SlowMist has not publicly tied CVE-2026-86950 to the wallet thefts it investigated earlier.
Questions readers ask
Has the Apple iPhone flaw been linked to crypto theft?
Apple has not said CVE-2026-86950 was specifically used to steal cryptocurrency, and SlowMist has not publicly established that the newly disclosed bug was the exact exploit in the wallet thefts it investigated. SlowMist does say the patch is highly relevant to iOS attack activity it has been tracking.
Which devices does CVE-2026-86950 affect?
The flaw affects a range of Apple devices, including iPhone 11 and later models, along with several recent iPad models. Apple fixed it by introducing improved bounds checking.
What should crypto users do about the iOS update?
SlowMist urged users to update their Apple devices and avoid suspicious links, files and app installation prompts. It also advised caution when downloading apps or opening content from unknown sources.
What was the FomoPeek app?
FomoPeek was a malicious iOS app that SlowMist investigated, and the firm said it received multiple reports of users losing digital assets with private key exposure. Some affected users had installed FomoPeek versions 1.1 and 1.2.