In short: Socket researchers discovered in September 2026 that 13 malicious WordPress themes had been quietly embedded in pirated streaming sites. Simply visiting one of those pages in Safari on an iPhone XS–16 running iOS 18.4–18.6.x triggered a two-stage exploit chain — CVE-2025-31277 and CVE-2025-43529 — granting attackers kernel-level access to the device. From there, everything was exposed: Keychain passwords, crypto wallet seeds, Wi-Fi credentials, messages, location data, and browsing history. Apple patched both vulnerabilities in iOS 26.1 and iOS 18.7.3 — update immediately if you have not done so.
What happened
In September 2026, Socket, a software supply-chain security firm, published a detailed breakdown of an attack campaign that had been running undetected for months. The attackers distributed 13 malicious WordPress themes through Packagist, targeting pirated streaming sites — primarily Vietnamese services hosting films and comics. The attack required just one action from the victim: opening such a page in mobile Safari.
Keeping up with threat reports like this is what our LiMP VPN blog is for — real incidents, practical takeaways, no filler.
How the exploit worked
JavaScript embedded in the malicious theme automatically detected the iOS version. If the device fell into the vulnerable range (iOS 18.4–18.6.x), a two-stage chain fired immediately:
- CVE-2025-31277 — a WebKit vulnerability that let page-level code escape the Safari sandbox.
- CVE-2025-43529 — a privilege escalation to kernel level, giving attackers full access to the device's protected storage.
The entire process took seconds and produced no pop-ups, permission prompts, or other visible signs. The victim saw nothing but the streaming site.
What data was at risk
With kernel privileges, attackers could reach a wide range of sensitive data:
- Keychain — iOS's system password store: logins to websites, banks, and corporate services.
- Wi-Fi passwords — including home and workplace networks.
- Crypto wallet seeds — in August 2026 the attackers expanded their target list to include Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX. Stealing a seed phrase means permanent, unrecoverable loss of funds.
- Messages and media — text messages, photos, call history.
- Cookies and browsing history — enough to hijack live web sessions.
- Location data — both current position and location history.
All attack infrastructure belonged to FUNNULL, a company on U.S. sanctions lists for cryptocurrency fraud. Data flowed directly to a group with a documented criminal track record.
Who was at risk
The vulnerable population included iPhone XS, XS Max, XR, and every model from the iPhone 11 through the iPhone 16 running iOS 18.4–18.6.x. Analysts estimated that hundreds of millions of devices worldwide were in that version range. The risk was real for anyone who visited a compromised streaming site in Safari on a vulnerable device — even if the page looked completely normal.
How to protect yourself
Update iOS right now. Both CVE-2025-31277 and CVE-2025-43529 are fixed in iOS 26.1 and iOS 18.7.3. Open Settings → General → Software Update and install the latest version. Turn on automatic updates so the next critical patch does not wait for a manual check.
Rotate your most important passwords. If your device was running iOS 18.4–18.6.x and you regularly visited unfamiliar or pirated sites in Safari, change passwords for critical services — banks, email, and work accounts. The LiMP VPN app protects your sessions in transit, but password rotation matters regardless of any VPN.
Check your crypto wallets. If any of the targeted wallets (Bitget, Phantom, Trust Wallet, OKX, and others) were installed on the device, review recent transaction history for unauthorised transfers. If anything looks suspicious, move assets to a new wallet with a fresh seed phrase generated on a clean device.
Add a network privacy layer. Kernel-level exploits are the domain of OS updates, not VPNs. But LiMP VPN for iOS encrypts your traffic end-to-end under a no-logs policy, shielding your browsing habits from your ISP and network operator — including which sites you visit. This matters most on public Wi-Fi, where traffic interception is simplest, and it reduces profiling exposure even when you land on an unfamiliar page. See plans and pricing.
