Skip to finding
important · Mobile — iOS

A trojanized iOS app carried an automatic eight-exploit kernel framework for sandbox escape and Keychain theft.

Affects

FomoPeek, a cryptocurrency-portfolio application installed on iPhones and iPads.

After the victim installs and launches FomoPeek 1.1 or 1.2, the framework fingerprints the device, selects a compatible kernel path, escapes the sandbox, and reaches other applications’ files and Keychain material without another prompt.

Detail and 2 sources
Chain to watch
Install and launch FomoPeek 1.1 or 1.2→↓Select a device-compatible kernel exploit→↓Escape the sandbox and steal cross-application secrets→↓The eight vulnerabilities and their per-release exploit mapping remain unidentified.
Unverified chainObtain the complete SlowMist and OKX sample report, exploit-module hashes, or a first-party mapping to fixed iOS releases.

The held evidence is secondary reporting and does not identify the vulnerabilities or the path used on each iOS release.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026