Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
1–10 of 101 posts
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#2(a)? This must be really bad.
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#3I got an alert this morning for an iOS update numbered 26.3.1(a). (a)? This must be really bad .
Description: A cross-origin issue in the Navigation API was addressed with improved input validation.
WebKit Bugzilla: 306050
CVE-2026-20643: Thomas Espach
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#4I got an alert this morning for an iOS update numbered 26.3.1(a). (a)? This must be really bad .
I wonder if this is supposed to be > iOS 18 or really just version 18?
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#5https://cloud.google.com/blog/topics/threat-intelligence/dar...
Relevant forward:
> GTIG has identified several different users of the DarkSword exploit chain dating back to November 2025. In addition to the case studies on DarkSword usage documented in this blog post, we assess it is likely that other commercial surveillance vendors or threat actors may also be using DarkSword.
> Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
> DarkSword supports iOS versions 18.4 through 18.7 and utilizes six different vulnerabilities to deploy final-stage payloads. GTIG has identified three distinct malware families deployed following a successful DarkSword compromise: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. The proliferation of this single exploit chain across disparate threat actors mirrors the previously discovered Coruna iOS exploit kit. Notably, UNC6353, a suspected Russian espionage group previously observed using Coruna, has recently incorporated DarkSword into their watering hole campaigns.
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#6Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#7I got an alert this morning for an iOS update numbered 26.3.1(a). (a)? This must be really bad .
> It can take over devices running iOS 18 that simply visit infected websites. I wonder if this is supposed to be > iOS 18 or really just version 18?
> DarkSword supports iOS versions 18.4 through 18.7
https://cloud.google.com/blog/topics/threat-intelligence/dar...
The source exploits continued to be patched with all of them patched in iOS 26.3
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#8Here is the Google Research group's writeup https://cloud.google.com/blog/topics/threat-intelligence/dar... Relevant forward: > GTIG has identified several different users of the DarkSword exploit chain dating back to November 2025. In addition to the case studies on DarkSword usage documented in this blog post, we assess it is likely that other commercial surveillance vendors or threat actors may also be using DarkS…
Re: Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
#9Earlier quoted context omitted.
> It can take over devices running iOS 18 that simply visit infected websites. I wonder if this is supposed to be > iOS 18 or really just version 18?
It's in the source article (from Google Research group): > DarkSword supports iOS versions 18.4 through 18.7 https://cloud.google.com/blog/topics/threat-intelligence/dar... The source exploits continued to be patched with all of them patched in iOS 26.3