
Apple has finally addressed a critical security vulnerability in its ImageIO framework, which could have allowed attackers to compromise cryptocurrency wallets and potentially drain user accounts. The company has released iOS 18.6.2 and iPadOS 18.6.2, along with macOS updates for Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8.
According to Apple, the vulnerability can be exploited by processing malicious images, which could corrupt memory and enable code execution. The company has confirmed that there have been reports of this exploit being used in the wild against specific individuals.
The security flaw is particularly concerning for cryptocurrency users who rely on their mobile devices as primary signing endpoints. As users often copy and paste recipient addresses, and many keep recovery phrases in screenshots or photo storage for convenience, an attacker could silently hijack the clipboard to swap addresses during a transaction, ultimately compromising user funds.
In addition to updating their iOS and iPadOS, Apple advises that users reduce their exposure by moving seed storage off photo libraries, reviewing app photo permissions, limiting clipboard access, and treating mobile wallets as hot environments with strict hygiene.
Source: cryptoslate.com