important · Mobile — iOS
A trojanized iOS app carried an automatic eight-exploit kernel framework for sandbox escape and Keychain theft.
Affects
FomoPeek, a cryptocurrency-portfolio application installed on iPhones and iPads.
After the victim installs and launches FomoPeek 1.1 or 1.2, the framework fingerprints the device, selects a compatible kernel path, escapes the sandbox, and reaches other applications’ files and Keychain material without another prompt.
Detail and 2 sources
Chain to watch
Install and launch FomoPeek 1.1 or 1.2→↓Select a device-compatible kernel exploit→↓Escape the sandbox and steal cross-application secrets→↓The eight vulnerabilities and their per-release exploit mapping remain unidentified.
Unverified chainObtain the complete SlowMist and OKX sample report, exploit-module hashes, or a first-party mapping to fixed iOS releases.
The held evidence is secondary reporting and does not identify the vulnerabilities or the path used on each iOS release.