10 ms·
Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
- joezydeco 6mo agoI got an alert this morning for an iOS update numbered 26.3.1(a). (a)? This must be really bad.
- FuriouslyAdrift 6mo agoImpact: Processing maliciously crafted web content may bypass Same Origin Policy Description: A cross-origin issue in the Navigation API was addressed with improved input validation. WebKit Bugzilla: 306050 CVE-2026-20643: Thomas Espach
- bombcar 6mo agoWhat device? I don't see anything beyond 26.3.1 on my iPhone 15 PromaxXDR™
- joezydeco 6mo agoiPhone 15 (vanilla) running iOS 18.7.2. I now have a permanent notification on my lock screen nagging me to update to iOS 26.
- qaz_plm 6mo agoEnabling beta updates for ios18 should kill the nagging notification.
- aurea 6mo agoThe update can be found under Settings > Privacy & Security > Background Security Improvements
- bombcar 6mo agoThere it is, and I've never seen that area before.
- dewey 6mo ago> It can take over devices running iOS 18 that simply visit infected websites. I wonder if this is supposed to be > iOS 18 or really just version 18?
- quentindanjou 6mo agoIt's in the source article (from Google Research group): > DarkSword supports iOS versions 18.4 through 18.7 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain https://cloud.google.com/blog/topics/threat-intelligence/dar... The source exploits continued to be patched with all of them patched in iOS 26.3
- dewey 6mo agoOh, I was confused why the article was so short and chalked it up to it being some developing story. Turns out there's a "You’ve read your last free article." heading that hides the rest but it's not very obvious that there's an article hiding.
- eugenekolo 6mo agoUnrelated bug as far as I can tell.
- jryio 6mo agoHere is the Google Research group's writeup https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain https://cloud.google.com/blog/topics/threat-intelligence/dar... Relevant forward: > GTIG has identified several different users of the DarkSword exploit chain dating back to November 2025. In addition to the case studies on DarkSword usage documented in this blog post, we assess it is likely that other commercial surveillance vendors or threat actors may also be using DarkSword. > Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine. > DarkSword supports iOS versions 18.4 through 18.7 and utilizes six different vulnerabilities to deploy final-stage payloads. GTIG has identified three distinct malware families deployed following a successful DarkSword compromise: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. The proliferation of this single exploit chain across disparate threat actors mirrors the previously discovered Coruna iOS exploit kit. Notably, UNC6353, a suspected Russian espionage group previously observed using Coruna, has recently incorporated DarkSword into their watering hole campaigns.
- alecco 6mo agoThis should be the post, not Wired's blogspam.
- bix6 6mo agoI know everyone hates liquid glass but isn’t that better security wise than being on an iOS that’s 8 versions behind?
- jryio 6mo agoThere are not 8 major versions between iOS 18 and iOS 26. Apple skipped the monotonously increasing version numbering system since iOS 1 during WDDC 2025 to adopt a year suffix based versioning system. iOS 17, then iOS 18, then iOS 26, then iOS 27. You're not the only party confused.
- BTAQA 6mo agoThe interesting angle here is what this means for passes and credentials stored in Apple Wallet. If device compromise is this accessible, the assumption that Wallet passes are isolated from the rest of the device needs more scrutiny. Apple's security model relies heavily on the secure enclave but a tool like this changes the threat surface significantly.
- ozlikethewizard 6mo agoThis is always the threat with walled garden style security. When you couple applications so tightly in an intrinsic trust network, on the basis that no external attacker can gain access, then the internal security is neglected and it only takes the weakest link.
- ramesh31 6mo agoWelp, I've been holding on out that liquid glass crap as long possible. Guess my phone is just going to suck now.
- bombcar 6mo agoIf it's really as bad as all that, they'll patch existing older releases.
- pfortuny 6mo agoOne can hope but I do not trust them.
- xoa 6mo ago>If it's really as bad as all that, they'll patch existing older releases. They have patched existing releases of iOS 18... but then they artificially restricted those patches only to a couple of phone models that don't support iOS 26. So if you're on a vaguely modern iDevice and are still on 18 because you don't want the new UI and other fuckups you are not allowed to install the patched 18. It'd be one thing if you had a phone that simply never supported iOS 18 at all, or if Apple wasn't patching iOS 18 at all for anyone, but that they've gone to the effort to fix it but then also used it as another lever for force upgrades is really sucky.
- JumpCrisscross 6mo ago> you are not allowed to install the patched 18 Is it “you are not allowed,” or Cupertino isn’t going to bother developing and testing?
- xoa 6mo ago>Is it “you are not allowed,” or Cupertino isn’t going to bother developing and testing? It is very firmly "you are not allowed". In fact you're not even allowed to switch back to iOS 18 at all. Only actively signed iOS IPSWs can be installed (barring historical cases where someone had saved signing tickets). You can see the current status at sites like https://ipsw.me https://ipsw.me and if you're on any iOS 26 supported iDevice currently only 26.3.1 is signed. The last iOS 18 version was 18.6.2 from August of last year. If you go back to the iPhone XS/XR, you'll see they're still updating iOS 18, with 18.7.6 released two weeks ago (March 4), but they've chosen to force anyone who wants security updates to move to iOS 26 instead.
- k2enemy 6mo agoI'm really hoping Apple backtracks on its refusal to update the 18.x line for phones that are compatible with 26. At least provide a security update.
- torben-friis 6mo agoTheir design disaster must be hidden in metrics, damn be security.
- lynndotpy 6mo agoApple used to have a really good security record, it's mind boggling they blew it all up just to force Liquid Glass on users. For those not in the loop, Apple used to provide security patches for supported older iOS versions. They changed a lot of behavior around the release of Liquid Glass (iOS 26, MacOS Tahoe). Starting with iOS 18.7.3, they only release patch versions for the iPhone XS and XR. They've repeated this, through to 18.7.6 now. So much goodwill and trust, obliterated.
- walterbell 6mo ago> Starting with iOS 18.7.3, they only release patch versions for the iPhone XS and XR. They've repeated this, through to 18.7.6 now. iPhone XS/XR: the only Usable + Secure iPhone in 2026
- yborg 6mo agoIt's especially glaring since Apple just released a fix for a Coruna exploit that patched iOS 15.
- titzer 6mo agoThose trillions of dollars aren't going to find their way into the pockets of the shareholders if they have to pay some rubes to maintain old stuff!
- 6510 6mo agoI'm always surprised what isn't a national security issue.
- hnburnsy 6mo ago>We also identified additional code added when the actor attempts to infect a user using Chrome, where the x-safari-https protocol handler is used to open the page in Safari (Figure 4). This suggests that UNC6748 didn't have an exploit chain for Chrome at the time of this activity. Thanks Apple for allowing the overriding of the user's default browser.
- MrDOS 6mo agoI wish I had a better sense of how these zero-click vulnerabilities work so I could get a sense of how to protect myself from them (you know, without giving in to Liquid Glass). Can they be blocked by an ad blocker? Are they blocked by any extant ad blockers? What about “Lockdown Mode”?
- fn-mote 6mo agoNote that this is 1-click. 0-click example: receive an MMS with a malformed image that exploits a bug in decoding
- rsync 6mo ago"0-click example: receive an MMS with a malformed image that exploits a bug in decoding ..." Consider a SMS firewall that: - flattens text to ascii-256 - recompresses, noises and slightly resizes images and video ... and only then passes the message onto your real (SIM card) phone number. This, of course, requires that you host your phone number somewhere like Twilio which has other added benefits like additional protection from SIM-jacking and being invulnerable to theft or loss of your handset, etc. Recommended.
- Lockal 6mo agoIf this firewall is available as a commercial product, eventually it be infected, so there won't be any need to hack any client devices. Since this is clearly a niche product, the device manufacturer won't be able to identify and fix bugs as effectively as companies like Apple do. This follows ROSKOMNADZOR recommendations: to install a middleware device that decrypts, stores, modifies, blocks and redirects all traffic depending on rules submitted from external party.
- rsync 6mo agoThis isn’t a product. This is a solution you build and run for yourself.
- DANmode 6mo ago
- throwaway2016a 6mo agoI was literally just attending a course on "innovation" and the topic of Apple vs Android was covered. Interestingly enough, a majority of students commenting cited iOS "security" as a core value proposition. As an Android user, however, I know there are a lot of CVEs in volume but in terms of severity, when an iOS issue happens it appears to generally be much more severe.
- eugenekolo 6mo agoIt's actually a fascinating find by Lookout, iVerify, and Google. This is a multi million dollar exploit chain sold to various buyers. Complete full chain 1-click exploit from Safari to complete device take over exfiltrating personal data, passwords, and crypto wallets. https://www.lookout.com/threat-intelligence/article/darksword https://www.lookout.com/threat-intelligence/article/darkswor... https://iverify.io/blog/darksword-ios-exploit-kit-explained https://iverify.io/blog/darksword-ios-exploit-kit-explained https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain https://cloud.google.com/blog/topics/threat-intelligence/dar...
- walterbell 6mo agoIs the full exploit chain functional on iPhone 17 MIE/EMTE silicon with Lockdown Mode enabled?
- eugenekolo 6mo agoNo, because Lockdown Mode disabled JIT which is a part of this exploit chain.
- _slih 6mo agothe supply chain for offensive tooling is now indistinguishable from the supply chain for malware. take care of your security team!
- geuis 6mo agoI'd like a security patch for 18. I have no desire to upgrade to iOS Vista or whatever it is we're calling it
- SayThatSh 6mo agoAll these exploits and we still can't get proper jailbreaks on new iOS versions :( I moved away from Android years ago in the interest of digital privacy so it's just wonderful to hear security isn't as tight as I'd hoped haha.. Then again I guess those like myself staying on the bleeding edge version-wise aren't affected.
- eugenekolo 6mo agoI suspect you'll see one with this or Coruna soon enough.
- Scrounger 6mo agoI'm on regular Android but thinking about switching to GrapheneOS for my next phone.
- seemizou92 6mo ago[dead]
- DavideNL 6mo agohttps://support.apple.com/en-us/126604 https://support.apple.com/en-us/126604 iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), macOS 26.3.2 (a) Released March 17, 2026 WebKit Available for: iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, macOS 26.3.2 Impact: Processing maliciously crafted web content may bypass Same Origin Policy Description: A cross-origin issue in the Navigation API was addressed with improved input validation. WebKit Bugzilla: 306050 CVE-2026-20643: Thomas Espach
- davidliu847386 6mo ago[flagged]
- TMille76489 6mo ago[dead]
- Officer_ASH96 6mo ago[dead]