Feed›Vulnerability›Malicious website themes infect outdated iPhones with spywar...
VulnerabilityCyber Insider
8.8 — CRITICAL

Malicious website themes infect outdated iPhones with spyware

📅 1 September 2026 at 19:51 UTC📰 Cyber InsiderView original source ↗
Malicious website themes infect outdated iPhones with spyware

Malicious website themes infect unpatched iPhones with spyware when users visit a compromised site, allowing attackers to steal messages, photos, passwords, location data, and cryptocurrency wallet recovery phrases. Socket’s Threat Research Team uncovered the packages on Packagist, where they were disguised as themes for OphimCMS and KKPhim, two Laravel-based content management systems used by Vietnamese … The post Malicious website themes infect outdated iPhones with spyware appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Malicious website themes infect outdated iPhones with spyware, allowing attackers to steal sensitive information such as messages, photos, and cryptocurrency wallet recovery phrases. The attack targets iPhones running vulnerable iOS releases, particularly iOS 18.4 through 18.6.x.

⚙️Technical Details
CVEs
CVE-2025-43529
Affected Systems
Apple iPhone OSiOSiPadOSmacOSSafaritvOSvisionOSwatchOS
Attack Vectors
NETWORK
💥Impact Assessment
Severity: high
Who Is at Risk
iPhone owners running vulnerable iOS releases, particularly iOS 18.4 through 18.6.x
🛡️Recommended Actions
1Install Apple's latest available software updates
2Remove themes distributed by the five affected Packagist vendors from OphimCMS and KKPhim websites
3Review sites for injected JavaScript
📦Affected Products
Apple IpadosApple Iphone OsApple MacosApple SafariApple TvosApple VisionosApple WatchosApple iPhone OSiOSiPadOS
🔐NVD Verified DataVERIFIED
CVE-2025-43529 ↗CVSS 8.8 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected Products (CPE)
Apple IpadosApple Iphone OsApple MacosApple SafariApple Tvos

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed