
Apple has released iOS 26.7.1 update to address a critical CoreGraphics flaw. Cybersecurity company SlowMist warns cryptocurrency wallet holders of targeted attacks.
AI-generated summary
Apple has released iOS 26.7.1 update to fix CVE-2026-86950 vulnerability in CoreGraphics, reported by Meta Product Security.
Only the paranoid survive. A trapped file is enough, and an unknown person's code executes on your iPhone. Apple released iOS 26.7.1 update on September 28. It closes a loophole that the firm already knows is being exploited. The calendar should worry crypto holders. Since mid-September, the cybersecurity company SlowMist has been tracking a wave of iOS attacks against wallets. The App Store had already served as a Trojan horse with these 26 trapped applications which targeted crypto investors.
iOS CoreGraphics flaw: what Apple pays lip service to
The vulnerability has the number CVE-2026-86950. It's housed in CoreGraphics, the engine that draws images, fonts and documents on your iPhone on the screen. This is out-of-bounds writing. In other words, the program writes data outside the memory area provided for it. An attacker can thus insert his own instructions. According to Apple's security bulletin, processing a malicious file can lead to the execution of arbitrary code.
The firm, however, remains short of details. It only refers to an “extremely sophisticated attack against specifically targeted individuals”. The exploitation would target versions prior to iOS 27. No figures on victims. It was Meta Product Security which reported the flaw to Apple.
The fix affects iPhone 11 and later models, as well as most recent iPads. Apple also pushed the same patch to macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. This is also a new zero-day flaw (exploited before the existence of a patch) for Apple. In February, the firm had already had to plug a breach of this type in the dyld component.
Crypto wallets on iPhone: why SlowMist sounds the alarm
Today, SlowMist relayed the fix on X, deeming it “very relevant”. Its teams are in fact monitoring ongoing iOS attack activity. “For crypto users, this is particularly concerning,” the company adds. She also says she has observed exploitation targeting sensitive wallet data.
Founded in 2018 in China, SlowMist audits protocols and tracks stolen funds for exchange platforms. It is a recognized reference in the sector. But it remains a private company, and its alert is not worth confirmation from Apple.
The only encrypted theft of the month goes through an application. FomoPeek released its versions 1.1 and 1.2 on the App Store on September 9 and 12. However, both contained two malicious modules. These modules exploited iOS flaws to escape the sandbox (the partition that isolates each app). They could then read the keychain, where iOS stores passwords and keys. SlowMist and the OKX security team traced approximately 580,000 USDT siphoned to the hacker's main address. A cleaned-up version 1.3 followed on September 17. Their kit, however, targeted versions of iOS 12 to 18.7.2.
Safari WYINCC attack: a second avenue to put into perspective
The second track follows a completely different mechanics. The SlowMist security manager, known by the pseudonym 23pds, reported the WYINCC attack chain. It is triggered from a simple web page opened in Safari, without the slightest additional click. The channel recycles techniques from DarkSword, a previously documented iOS exploit channel. However, its targets remain iPhones running iOS 18.4 to 18.6.2, exposed to flaws that have already been corrected. SlowMist also indicated to Cointelegraph that it had not confirmed any crypto theft in the sample analyzed.
A downside is nevertheless necessary. Apple has not linked CVE-2026-86950 to FomoPeek or any wallet. For now, the link between this flaw and attacks against cryptos is up to SlowMist's interpretation. No public evidence establishes this. But a flaw exploited against “targeted individuals” generally targets high-value profiles. A well-stocked crypto portfolio is one of them.
iOS update: the gesture that costs five minutes
The parade is contained in a menu. Go to Settings > General > Software Update. Then install the latest version available on all your Apple devices, including iPhone, iPad and Mac. Under iOS 26, version 26.7.1 therefore constitutes the bare minimum. On the other hand, devices already running iOS 27 escape this flaw.
SlowMist also recommends avoiding applications from unknown sources. Also avoid opening questionable links in Safari or in-app browsers. Finally, treat any unexpected files or installation prompts with suspicion.
There remains the case of hot wallets, these permanently connected wallets installed on the phone. If your iPhone has hosted FomoPeek 1.1 or 1.2, caution is advised. Same thing if it went a long time without updating with a serious sum in a hot wallet. In this case, SlowMist recommends generating a new recovery phrase on an up-to-date device. Then transfer the funds to this new wallet. It’s tedious, we grant you, but much less than a wallet emptied overnight.
AI outlook — possibilities, not facts
Installation of iOS 26.7.1 update by affected users
Likely · Within days

NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.

China's Ministry of State Security claims that the anonymity of cryptocurrencies is an illusion, explaining that all transactions leave traceable traces via fiat-crypto exchanges and IP addresses, and cites the Bitfinex affair as proof, while banning the use of Bitcoin on its territory despite tolerance of detention.

Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers, publicly asking for help on Discord and Telegram when their XRP-bitcoin swaps on THORChain fail, captures of support tickets and transactions show.

On-chain analyst Wazz claims to have identified a coordinated operation linked to 53 memecoin launches on Robinhood Chain, which extracted at least $18.43 million between July 10 and September 21, by exploiting a loophole in the Pons V2 anti-sniping tax to concentrate the supply and immediately resell to investors.

The UNCTAD statistics portal (UNCTADstat) underwent a massive automated collection of 16,000 requests between April and June 2026. IP addresses and identifiers suggest a link to OpenAI agents, although the site only contains public data.

Solana is testing Alpenglow, an overhaul of its consensus replacing TowerBFT and Proof of History. This protocol aims to reduce transaction finality from 12.8 seconds to 150 milliseconds, improving efficiency for payments and bridges.