DarkSword iOS Exploit: Is Your iPhone Still Vulnerable?

Six iOS flaws chained in JavaScript gave attackers root on an iPhone from one page load. The code is public. Here is how to check your exposure.

Share
DarkSword iOS Exploit: Is Your iPhone Still Vulnerable?

DarkSword is a six-vulnerability iOS exploit chain that silently compromises an iPhone the moment a vulnerable device loads an infected page — no tap, no download, no warning. Lookout Threat Labs identified at least three separate hacking groups deploying it against real targets; the full exploit code leaked to GitHub in March 2026. The chain has been in active use since at least November 2025, and it is fully patched in iOS 26.3 and later. If you are still running iOS 18.4 through 18.7.4, your device is exposed.

What you need to know:

  • DarkSword chains six CVEs in JavaScript to take root-level control of an iPhone through Safari — no interaction beyond loading the page
  • Three payload families have been observed: GHOSTBLADE, GHOSTKNIFE and GHOSTSABER, each tied to a different operator. GHOSTBLADE steals messages, photos, credentials, location data and cryptocurrency wallet access, then attempts to delete itself
  • Three separate groups deployed DarkSword before the complete exploit code was published to GitHub on 23 March 2026, confirmed authentic by independent researchers
  • iOS 27 is current, and all six flaws are patched in iOS 26.3 or later. Apple also shipped iOS 18.7.7 for users who cannot move off iOS 18 — first on 24 March 2026 to a handful of older devices, then widened on 1 April 2026 to a far larger pool
  • Lockdown Mode stops DarkSword on vulnerable iOS versions, at the cost of significant app and website functionality

From intelligence agency tool to GitHub download

The iOS zero-day market has always had a trickle-down problem. Exploit chains with iOS remote code execution capability routinely sell for $1 million or more on the private market — buyers are primarily intelligence agencies running targeted operations against journalists, dissidents, and foreign officials. At that price, you're not mass-targeting iPhone owners; you're burning expensive capabilities on specific, high-value individuals.

The secondary market is different. Commercial surveillance vendors — companies that buy or license government-grade exploits and resell access to state clients — don't apply the same operational discipline. PARS Defense, a Turkish commercial surveillance vendor, is one of three groups identified using DarkSword by Google's Threat Intelligence Group. Their clients run broader campaigns. Broader targeting means sloppier execution, which means exposure.

DarkSword's GitHub publication is the end of that chain. Apple's lock screen security alerts — behavior the company has not deployed before for active iOS exploits — are the company acknowledging something has changed structurally, not just patching one incident.


What DarkSword actually does

DarkSword is written entirely in JavaScript and runs inside Safari. That's unusual for a government-grade iOS exploit chain — most operate at a lower level. Running in a high-level interpreted environment means the chain can bypass iOS mitigations including Pointer Authentication Codes (PAC) and Trusted Page Reference Owner (TPRO), while remaining portable enough that three completely different groups picked it up and deployed it.

The kill chain runs in stages, and the components matter because the patch versions differ. Delivery starts when a victim visits a compromised or attacker-controlled page in Safari, which loads rce_loader.js and fingerprints the device for its iOS version before proceeding. The renderer stage then uses one of two JavaScriptCore memory corruption bugs — CVE-2025-31277 or CVE-2025-43529 depending on the target's iOS version — to achieve code execution inside the WebContent process.

From there CVE-2025-14174, a memory corruption bug in ANGLE, Apple's GPU rendering stack, injects code into the mediaplaybackd system daemon through WebGPU and escapes the WebContent sandbox entirely. The anchor vulnerability is CVE-2026-20700, a flaw in dyld, the dynamic linker — and it is not the initial entry point. It is the PAC and TPRO bypass that disables Apple's two most significant kernel integrity protections, and Apple's own advisory describes it as used in an "extremely sophisticated attack". The flaw is reported to have sat in the dyld code path for nearly two decades.

The final privilege escalation to root runs through two kernel bugs, CVE-2025-43510 and CVE-2025-43520. JavaScriptCore is then force-injected into system daemons including configd, wifid, securityd and UserEventAgent, from which the payload stages and exfiltrates data before deleting its staged files and exiting. Total device dwell time is measured in minutes rather than a persistent implant — a deliberate trade that reduces forensic detectability at the cost of ongoing access.

UNC6353, the Russia-linked group, delivered the chain through a watering hole attack: they compromised multiple Ukrainian news and government websites, injected the malicious JavaScript, and waited. Visitors on vulnerable iOS devices were compromised the moment the page finished loading. Notably, they only ever used the exploit modules for iOS 18.4 through 18.6, even though an iOS 18.7 build was available to them.

Once root access is established, the payload deploys. The three families are worth separating:

  • GHOSTBLADE — a data miner used by UNC6353. It extracts iMessage conversations, Telegram and WhatsApp data, email, call history, contacts, browser history, photos, and location data. It also specifically targets a long list of cryptocurrency wallet apps: Coinbase, Binance, Kraken, KuCoin, OKX, MetaMask, Exodus, Phantom, Ledger, and Trezor, among others.
  • GHOSTKNIFE — deployed by UNC6748, adds microphone audio recording, screenshots, and the ability to pull additional files down from its command server. It erases crash logs periodically to cover its tracks.
  • GHOSTSABER — the least-documented of the three, used by PARS Defense. Device enumeration, file listing and data exfiltration, with audio recording referenced in code but not yet implemented.

That breadth of crypto targeting is unusual for a state espionage actor. Lookout researchers assess that UNC6353 operates partly as a financially motivated group, running cybercrime operations alongside their government-adjacent work. After exfiltration, the payload attempts to delete its own traces — UNC6353's implementation missed crash logs and browsing history entirely, which is part of how analysts confirmed what had run on affected devices.


Who is being targeted

Google's Threat Intelligence Group has tied DarkSword deployments to four countries, and the split between espionage and commercial surveillance is the interesting part.

  • Ukraine — UNC6353, a suspected Russian espionage group, using watering holes against news, e-commerce and industrial equipment sites
  • Saudi Arabia — UNC6748, an unattributed state or state-adjacent actor, running a Snapchat-themed decoy site at snapshare[.]chat that redirected visitors into the chain
  • Turkey and Malaysia — PARS Defense, a Turkish commercial surveillance vendor selling access to state clients

PARS Defense also added its own operational security improvements over UNC6353's deployment, encrypting exploit stages in transit with ECDH key exchange. That detail matters: it shows independent technical teams adapting the same kit for different customers, rather than one group sharing tooling.


Why the Russian group got caught — and how DarkSword was found

Lookout Threat Labs were already investigating Coruna — a separate iOS exploit kit targeting iOS 13 through 17.2.1 — when a detail stood out. A new domain had been registered on the exact same day as a known Coruna-linked domain. Several of its sub-domains pointed to the same IP addresses. That shared infrastructure is what led researchers to DarkSword.

The new domain was hosting JavaScript files with obvious names and no obfuscation. The code was clean, well-commented, and peppered with emojis — a pattern consistent with AI-assisted development. The name "DarkSword" appeared explicitly in the source multiple times. When Lookout researchers loaded the exploit against test iPhones, the phones crashed. Repeatedly. They had to fix UNC6353's own implementation bugs locally to get the chain to run at all.

The picture that emerges: UNC6353 purchased a sophisticated, commercial-grade exploit kit and lacked the technical depth to deploy it. The other two groups using DarkSword — PARS Defense and UNC6748 — were professional enough to avoid exposing their infrastructure. UNC6353's sloppiness is the reason DarkSword is public knowledge at all.

One practical note worth filing here: rebooting your iPhone regularly cuts off in-memory implants that don't survive a restart. DarkSword's payload already exits after exfiltration, so this is not specific to this chain, but it matters more as mobile implants get more common.


The GitHub leak and what came after

Lookout and Google's Threat Intelligence Group declined to publish the full DarkSword code after discovery. The reasoning was direct: the chain is simple to deploy and the exposure would be widespread. TechCrunch reported that an unidentified person published the complete exploit to GitHub three days later, on 23 March 2026. Security researchers confirmed on X that the published code is authentic.

The effect was fast. Additional threat actors — including TA446 — were observed deploying the leaked version in spear-phishing campaigns within days. A chain that required buying access from a commercial surveillance vendor now required a GitHub account.

The regulatory response was equally fast. CISA added the dyld flaw to its Known Exploited Vulnerabilities catalog and ordered US federal agencies to remediate, alongside the other DarkSword flaws. Apple's advisory assigned CVE-2026-20700 a CVSS score of 7.8.


Who is vulnerable, and what to do

The chain requires iOS below 18.7.5, or below 26.3 on the iOS 26 branch. The six CVEs were patched progressively — CVE-2025-43510 and CVE-2025-43520 in iOS 18.7.2 and 26.1, CVE-2025-43529 and CVE-2025-14174 in iOS 18.7.3 and 26.2, and the dyld flaw CVE-2026-20700 in iOS 26.3.

As of October 2026 the picture has moved on. iOS 27 shipped on 14 September 2026, with 27.0.1 following on 28 September. iOS 26 remains on security support but its active support window ended when iOS 27 arrived. The practical advice is unchanged but the version numbers are not:

  • If your device supports iOS 27: update to it. Done.
  • If you're staying on iOS 26: update to the latest point release. All DarkSword flaws were patched by 26.3.
  • If you're staying on iOS 18: update to iOS 18.7.7. Apple released it first on 24 March 2026 for the iPhone XS, XS Max, XR and 7th-generation iPad — devices that cannot run iOS 26 at all — then widened availability on 1 April 2026 after users on newer hardware who had not upgraded to iOS 26 found themselves stranded on vulnerable 18.x builds with no point updates arriving. That second release is the one most people needed.
  • If you cannot or will not update: enable Lockdown Mode. It blocks DarkSword even on unpatched iOS versions. The tradeoffs are significant — certain apps fail, websites stop loading correctly, font rendering breaks. Settings → Privacy & Security → Lockdown Mode. It's a real restriction of normal iPhone functionality, and it's worth knowing about before you need it.

How many devices are still exposed is genuinely uncertain, and the estimates disagree. Malwarebytes cited Apple figures suggesting roughly a quarter of iPhone and iPad users remained on iOS 18 or earlier, while iVerify estimated up to 270 million iPhones were on vulnerable versions at the time of disclosure. Treat any single figure with caution; the direction is what matters, and it is hundreds of millions of devices. Unlike targeted spyware campaigns, DarkSword doesn't require the attacker to know who you are — any visitor to an infected site on a vulnerable iOS version is a candidate.

Beyond the immediate update, there's a broader iOS security baseline that most iPhone users haven't fully configured. The iPhone Privacy Setup Guide covers the settings Apple doesn't surface prominently, many of which limit what an attacker can access even if they do gain entry. And how you lock your device matters — a strong passcode is the last line of defense if an implant exfiltrates your unlock credentials.

Apple's lock screen alert reads: the company "is aware of attacks targeting out-of-date iOS software, including the version on your iPhone." That wording confirms active, ongoing exploitation — not theoretical risk. If you received that notification and haven't updated yet, this is what it was referring to.


The bigger issue

DarkSword isn't a one-off. It's the most recent example of a pattern researchers have documented repeatedly: sophisticated iOS exploits that start in targeted government operations eventually reach groups with no operational discipline about who they target. A chain that would have cost hundreds of thousands of dollars on the private exploit market three months ago is now a GitHub repository with a confirmed-authentic tag from the security community.

Apple's lock screen alerts are unusual precisely because the company rarely acknowledges active exploitation publicly and directly. The fact that they pushed notifications here signals that the exposure is real, the affected population is large, and the barrier to exploitation has dropped below what quiet patching can handle. Update your phone.


Your passwords are also at risk. GHOSTBLADE specifically targets saved credentials. If you use reused passwords across sites, one compromised iPhone means one compromised everything. 1Password generates and stores unique passwords per account — so a stolen credential from one site doesn't cascade. Worth setting up regardless of DarkSword.
## Convertkit Newsletter