Apple Patches iPhone CoreGraphics Zero-Day Exploited Against Crypto Wallets
Security
Bearish

Apple Patches iPhone CoreGraphics Zero-Day Exploited Against Crypto Wallets

Apple released a security patch on September 29 for a zero-day CoreGraphics vulnerability that was being actively exploited to target iPhone crypto wallets. Security firm SlowMist warned users that the flaw was used to extract sensitive wallet data before the patch became available.

Sep 30, 2026, 07:27 PM1 min read

Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work

The Vulnerability and Active Exploitation

Apple patched a zero-day flaw in iOS CoreGraphics on September 29 after the vulnerability was discovered being exploited in the wild. Security research firm SlowMist documented active attacks using the CoreGraphics flaw to target users of cryptocurrency wallet apps on iPhone, with attackers focusing on extracting sensitive wallet-related data.

Risk to Crypto Users

The CoreGraphics module handles low-level graphics rendering on iOS, giving an attacker who exploits it potential access to visual data rendered on-screen. For crypto wallet users, this could theoretically expose private keys, seed phrases, or transaction details displayed in the app's UI before they are cleared from memory. SlowMist warned that users of iPhone-based wallets should update to the latest iOS version immediately to close the attack surface.

Patch Availability

Users can access the patch through Apple's standard iOS update mechanism. Apple did not publicly name the vulnerability or provide technical details of the CoreGraphics flaw in its security advisory, a common practice for zero-days patched shortly after discovery. The firm has not disclosed the number of users affected or whether any wallets reported unauthorized access tied to the exploit.

Why It Matters

For Traders

Traders with funds held on iPhone wallets should update iOS immediately; exchanges and platforms may see temporary withdrawal delays as users secure devices.

For Investors

Persistent zero-day vulnerabilities in mainstream device operating systems highlight custodial and security risks that drive institutional adoption of cold storage and regulated custodians.

For Builders

Wallet developers should implement additional safeguards against graphics-layer attacks, such as obfuscating sensitive data rendering and using secure enclaves where available.

This article is for information only and is not financial advice. Read the full disclaimer.

Related Articles

Latest News