New iOS Exploit Uses Advanced iPhone Hacking Tools to Steal Personal Data
ID: 1e331af6-df46-51cc-bfb9-ef618b64b4fc
STIX ID: report--1e331af6-df46-51cc-bfb9-ef618b64b4fc
Feed Name: GBHackers
Google Threat Intelligence Group (GTIG) reports the discovery of DarkSword, a JavaScript-only iOS full-chain exploit active since November 2025 that chains six vulnerabilities (including multiple zero-days and listed CVEs) to fully compromise devices running iOS 18.4–18.7; it has been used by at least three actors (UNC6748, PARS Defense, UNC6353) to deploy GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE for data theft and espionage, Apple patched the flaws in iOS 26.3, and users—especially high-risk targets—are advised to update and enable Lockdown Mode.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
