New "DarkSword" exploit targets millions of iPhone devices via compromised
Security researchers from Google's Threat Intelligence Group alongside firms Lookout and iVerify have identified a sophisticated new hacking tool called DarkSword that silently steals sensitive user information when victims visit infected web pages without their knowledge, specifically targeting iOS devices running vulnerable patches between 18.4 to the latest available versions before patching in later releases like version X.X (note: source text mentions conflicting numbers such as "iOS 26" and "version 3", but consistently identifies older unpatched software variants).
Key Points
-
1DarkSword is identified as an active fileless hacking tool that targets iPhones by exploiting system vulnerabilities when users visit malicious websites.
-
2The attack exploits a chain of iOS 18.4 to 18.7 flaws, allowing it to steal sensitive data like messages and passwords without installing traditional spyware on the device.
Developments
Perspectives
DarkSword is described as an advanced fileless hack that targets iPhones by exploiting system processes through malicious web pages to steal sensitive data without installing traditional spyware.
— [Mar 20, 14:59] Using An iPhone? One Wrong Website Visit Could Put Your Data At Risk (News.abplive.com)The tool DarkSword exploits multiple vulnerabilities in iOS versions ranging from version number to , allowing it to silently take over iPhones the moment a user visits an infected website.
— [Mar 18, 20:45] New iPhone hacking tool puts hundreds of millions of devices at risk (Cultofmac)A newly identified set of iOS vulnerabilities is central to this attack method known as DarkSword. Researchers from Google's Threat Intelligence Group and cybersecurity firms Lookout have found that multiple flaws in Apple mobile operating systems create a new pathway for hackers.
— [Mar 19, 06:25] A vulnerability chain exposes iPhone attackers (Thehindu)Hackers are using the Darksword malware to steal personal photos and passwords from users who have missed updates. The software specifically targets older iOS versions within a very short timeframe.
— [Mar 18, 09:45] Apple's new vulnerability chain exposes iPhone attackers (Static.winfuture.de)'DarkSword' is an advanced fileless hack that exploits system processes through malicious web pages to steal sensitive data without installing traditional spyware. It targets iPhones running older software.
— [Mar 19, 06:25] A vulnerability chain exposes iPhone attackers (Thehindu)