Pubblicata il 10 set 2026 · Abbiamo verificato il 10 set 2026 che è ancora attiva
Questa azienda è tua?US$ 20.000 – US$ 50.000 per progetto
Implementation of exploiting iOS browser vulnerabilities to steal seed phrases and WhatsApp and Telegram keys Attack Framework DarkSword: Targets iOS 13 through 18.7, exploiting Safari vulnerabilities through malicious webpages to achieve remote code execution (RCE). Includes 23 exploits covering multiple iOS versions. Detailed Attack Flow Bait delivery: Victims are lured through fake adult livestreaming sites, TRON energy platforms, cryptocurrency trading pages, or legitimate websites compromised with hidden iframes for watering-hole attacks. Exploit execution: Once the victim visits the page, a JavaScript framework fingerprints the device and delivers the appropriate WebKit RCE exploit. Sandbox escape: Kernel vulnerabilities are chained to escalate privileges from the browser sandbox to the system level. Payload deployment: The payload is injected into system processes and scans installed cold-wallet apps for BIP39 seed phrases. Data exfiltration: Stolen data is transmitted in real time through a Telegram bot. Key Attack Characteristics Zero-interaction exploitation: Data can be stolen simply by visiting the malicious webpage. Persistent access: The attack code continues running in the background even after the webpage is closed. Cross-app data theft: After escaping the sandbox, the attacker can gain unauthorized access to data stored in other apps’ sandboxes. The iOS Sandbox is one of the core security mechanisms protecting legitimate applications on Apple’s iOS operating system. Its basic principle is that each app runs within its own isolated directory and memory space, preventing it from accessing system resources or data belonging to other apps. Each app operates inside a separate sandbox environment, creating a built-in security barrier. As iOS evolved, Apple’s sandboxing policy shifted from an early blacklist-based model, which blocked known dangerous APIs, to a whitelist-based model, which denies access by default and permits only trusted interfaces approved by Apple. A sandbox escape occurs when an attacker exploits system vulnerabilities to break out of this restricted environment, allowing code to run with privileges far beyond those granted to a normal application.
Crea un account gratuito per vedere l'offerta completa e candidarti.