A compromised streaming page can take an unpatched iPhone to kernel access and steal secrets.
JavaScriptCore renderer corruption → GPU process → Apple driver race → kernel read/write.
Apple iPhone XS through iPhone 16 running vulnerable iOS 18 releases when Mobile Safari loads a site using one of 13 trojanized OphimCMS or KKPhim Packagist themes.
Drive-by spyware execution with kernel memory access and bulk credential, message, photo, and cryptocurrency-wallet-secret exfiltration
The exploit chain reaches kernel read/write through renderer corruption and the GPU process; the spyware collects secrets from the handset.
Detail and 2 sources
The campaign began with an attacker-controlled Packagist theme served by a streaming site. The victim needed only to load the affected page in Mobile Safari.
JavaScriptCore supplied renderer read/write; Mach and IOSurface primitives then reached the GPU process and an Apple driver race supplied kernel read/write.
Collection included keychains, Wi-Fi credentials, messages, photos, cookies and account data. An August redeployment added wallet seed phrases.
Apple published updates, but the assessed boundary remains open on end-of-life hardware and the capability is not fully removed.
- access:network:internet
- reachable from the public internet
- Reaches end-of-life hardware
- Yes
The definite conclusions are limited to the documented exploit chain; build-specific signing state and undocumented recovery or alternate interfaces remain unverified.