ConciseSignal
Following

Fake iPhone Duo preorder site exploits unpatched iPhones

Security researchers at Malwarebytes discovered a fraudulent iPhone Duo preorder website using the DarkSword exploit chain to attack older, unpatched iPhones. Simply loading the website is enough to trigger the exploit, which attempts to steal saved passwords, cryptocurrency wallet data, photos, and personal notes. The scam specifically targets iPhones with iOS versions 18.4 through 18.6.2 and does not affect iPads or Macs, according to Malwarebytes.

Why it mattersThe attack can compromise a device without any user interaction, posing significant risks for anyone with an unpatched iPhone. Cryptocurrency funds and other sensitive information could be stolen if the exploit succeeds.

Sources covering this

CNETLook Out for This iPhone Duo Preorder Scam That Can Steal Your Data8:31 PM →Tom's GuideScammers are using iPhone Duo pre-orders to try and steal your passwords — here's how to stay safe11:25 AM →9to5MacFake iPhone Duo preorder page can steal crypto wallet data and more1:33 PM →AppleInsiderHeadline onlyPSA: Do not open links to an early iPhone Duo pre-order page2:32 PM →

How it unfolded

  • CNET Look Out for This iPhone Duo Preorder Scam That Can Steal Your Data
  • Tom's Guide Scammers are using iPhone Duo pre-orders to try and steal your passwords — here's how to stay safe
  • 9to5Mac Fake iPhone Duo preorder page can steal crypto wallet data and more
  • AppleInsider PSA: Do not open links to an early iPhone Duo pre-order page

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity