BTC—ETH—BNB—SOL—XRP—USDC—TRX—ADA—DOGE—
Data by CoinGecko
Scam Watch▼Bearish

Zero-Day Graphics Patch Linked To Mobile Crypto Wallet Theft

A newly patched zero-day vulnerability in mobile device graphics rendering is being tied to targeted attacks against digital asset holders. The exploit allows attackers to execute arbitrary code simply by having the victim's device process a specially crafted file.

Arbitrary Code Execution

The flaw, designated as CVE-2026-86950 with a CVSS score of 8.8, affects older operating system versions. On Monday, an update was released for iOS 26.7.1 and iPadOS 26.7.1 to address the issue. The vulnerability exists within CoreGraphics, the framework utilized for 2D graphics manipulation. It involves an out-of-bounds write, which happens when a program attempts to store data outside its allocated memory boundaries. This overflow corrupts adjacent memory, allowing malicious actors to redirect the software. When the graphics framework parses a booby-trapped file, the attacker's code runs automatically. The issue was resolved by implementing improved bounds checking.

Ensar Seker, the CISO at SOCRadar, told Dark Reading that this type of memory-corruption bug could facilitate a zero-click or low-interaction attack chain if combined with an appropriate delivery method. The exact mechanism used to deliver the malicious files to victims remains undisclosed. Meta Product Security was credited with originally reporting the bug. The technology manufacturer acknowledged a report indicating the flaw was potentially leveraged in an “extremely sophisticated attack” against specific users on earlier system versions, though it declined to name the attackers, the targets, or the number of affected devices.

Zero-Day Graphics Patch Linked To Mobile Crypto Wallet Theft
Arbitrary Code Execution The flaw, designated as CVE-2026-86950 with a CVSS score of 8.8, affects older operating system versions.

Digital Asset Security Risks

On Tuesday, blockchain security researchers highlighted a potential connection to the digital asset sector. The security firm SlowMist stated the operating system update is “highly relevant” to ongoing exploitation activity aimed at extracting sensitive crypto wallet information. Additionally, SlowMist CISO 23pds indicated in a separate post that the patched zero-day was actively utilized in attacks compromising cryptocurrency wallets.

The official security advisory makes no specific mention of cryptocurrency, and independent verification linking CVE-2026-86950 to a specific digital asset theft has not been published. However, the US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on Tuesday due to evidence of active exploitation. This warning arrives shortly after a September 19 report regarding stolen crypto assets from users who installed versions 1.1 and 1.2 of an application called FomoPeek. An investigation conducted by SlowMist alongside OKX uncovered an iOS kernel exploitation framework containing eight exploit methods within those application builds. Researchers have not explicitly stated whether the FomoPeek campaign utilized this specific CoreGraphics vulnerability.

Patches were also issued for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Current generation systems, including iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1, do not appear to be affected and shipped without published CVE entries. Users currently operating on iOS 26 are advised to either install the 26.7.1 update or move to iOS 27. Security experts recommend that crypto holders exercise caution with unexpected files or links opened within Safari or in-app browsers, and completely avoid applications originating from untrusted sources.

← All stories