logo

DarkSword Exploit Chain Leaked Online, Posing Risk to Millions of iPhones

ID: 8b10a470-7ff5-5442-bee8-b371e010cad1

STIX ID: report--8b10a470-7ff5-5442-bee8-b371e010cad1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers report that the DarkSword iOS exploit chain — a JavaScript-based, in-memory exploit kit — is available outside its original operators and has been used to achieve kernel read/write on iOS devices via watering-hole pages, bypassing mitigations and pivoting through GPU and kernel vulnerabilities to deploy infostealer payloads (GHOSTBLADE, GHOSTKNIFE, GHOSTSABER). Attribution is made to UNC6353 with observed targeting across multiple countries; administrators are urged to update to iOS 26.1+ and consider Lockdown Mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.