Apple has released updates to address a significant security vulnerability impacting iPhone and iPad devices, specifically through iOS 26.7.1 and iPadOS 26.7.1. The flaw, tracked under the code CVE-2026-86950, was potentially used in sophisticated attacks targeting specific individuals using versions prior to iOS 27. The cybersecurity firm SlowMist emphasized that this vulnerability warrants close monitoring, especially for cryptocurrency users.
Technical Breakdown and Apple’s Response
The vulnerability was found within the CoreGraphics component of Apple’s operating systems. It allowed attackers to execute arbitrary code on a device by processing a maliciously crafted file. Apple identified the problem as an “out-of-bounds write” error, where malicious data could spill outside the allocated memory area, disrupting system behavior and potentially allowing the attacker to run desired commands. The issue was reported to Apple by Meta Product Security, prompting an enhancement of boundary checks to resolve the flaw. No confirmation has been provided yet about its direct use in cryptocurrency theft.
SlowMist, highlights that the iOS and iPadOS 26.7.1 update addresses the CVE-2026-86950 vulnerability, which facilitates arbitrary code execution.
Implications for Cryptocurrency Users
Blockchain security firm SlowMist has drawn attention to the update due to recent iOS-based attack activities. The vulnerability appears highly related to previously observed iOS attack patterns, posing a notable risk, particularly because of its potential to target sensitive wallet data. Nonetheless, neither Apple nor SlowMist has publicly confirmed the CVE-2026-86950 vulnerability as the exact method used in studied wallet theft cases. Current assessments are based on observed attack patterns and technical similarities.
SlowMist underscores that the primary concern for cryptocurrency users stems from the vulnerability’s possible connection to iOS exploits targeting sensitive wallet data.
FomoPeek Review Raises Concerns
The advisories follow SlowMist’s recent examination of a malicious iOS application named FomoPeek. This app reportedly contained kernel-level exploitation tools capable of bypassing Apple’s application isolation, potentially granting access to data from other apps. FomoPeek’s malicious versions were found to gain elevated privileges, allowing access to Keychain data and files stored by other applications. The Keychain represents the core security infrastructure for storing passwords and sensitive credentials on Apple devices.
Furthermore, FomoPeek included multiple attack methods targeting various iOS versions, designed to circumvent Apple’s typical application restrictions. This scenario has underscored the importance of timely security updates, particularly for users holding digital assets in mobile wallets.



