logo

DarkSword: Researchers uncover another iOS exploit kit

ID: f3ee8e99-7942-5962-9706-ce7dbbbdf5af

STIX ID: report--f3ee8e99-7942-5962-9706-ce7dbbbdf5af

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Google and iVerify disclosed 'DarkSword', a sophisticated JavaScript iOS exploit chain used since November 2025 that combines six vulnerabilities across WebKit, the iOS/macOS kernel, and dyld to escape the WebContent sandbox, gain kernel read/write, and exfiltrate sensitive data (passwords, keys, files, crypto wallets). The toolkit has been observed in multiple targeted campaigns attributed to state-linked actors (UNC6353, UNC6748) and customers of a Turkish commercial surveillance vendor (PARS Defense); Apple released multiple patches (iOS 18.6–26.3 series) and researchers recommend updating to iOS 18.7.6 or 26.3.1 or enabling Lockdown Mode if updates are not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.