DarkSword: Researchers uncover another iOS exploit kit
ID: f3ee8e99-7942-5962-9706-ce7dbbbdf5af
STIX ID: report--f3ee8e99-7942-5962-9706-ce7dbbbdf5af
Feed Name: Help Net Security
Google and iVerify disclosed 'DarkSword', a sophisticated JavaScript iOS exploit chain used since November 2025 that combines six vulnerabilities across WebKit, the iOS/macOS kernel, and dyld to escape the WebContent sandbox, gain kernel read/write, and exfiltrate sensitive data (passwords, keys, files, crypto wallets). The toolkit has been observed in multiple targeted campaigns attributed to state-linked actors (UNC6353, UNC6748) and customers of a Turkish commercial surveillance vendor (PARS Defense); Apple released multiple patches (iOS 18.6–26.3 series) and researchers recommend updating to iOS 18.7.6 or 26.3.1 or enabling Lockdown Mode if updates are not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
