Drooid Logo
Back to story perspectives

Full Breakdown

Widespread Vulnerability: DarkSword Exploit Targets iPhones

3/18/2026, 10:45:50 PM

Overview of the DarkSword Exploit

Recent research has unveiled a significant cybersecurity threat known as DarkSword, a sophisticated iPhone hacking technique capable of compromising hundreds of millions of devices. This exploit has been embedded in various Ukrainian websites, allowing hackers to silently take control of iPhones running outdated versions of iOS, particularly versions 18.4 to 18.6.2. Researchers from Google, iVerify, and Lookout have identified that this vulnerability affects a substantial number of users, with estimates suggesting that between 220 million and 270 million iPhones remain exposed due to users not updating their devices.

Key Findings and Mechanism of Attack

DarkSword operates through a "watering-hole" attack strategy, where compromised websites deliver the exploit to iPhones visiting them. This method restricts the attack to users geolocated within Ukraine, indicating a targeted surveillance effort amid ongoing geopolitical tensions. The malware is designed for rapid data extraction, capable of stealing sensitive information such as passwords, authentication tokens, and cryptocurrency wallet data within minutes before self-deleting to minimize detection.

Broader Implications and Context

The emergence of DarkSword follows the discovery of another exploit named Coruna, which has been linked to Russian state-sponsored hacking efforts. Both tools highlight a growing trend in the accessibility of sophisticated mobile spyware, previously reserved for state-level operations. Rocky Cole, co-founder of iVerify, noted that the careless exposure of DarkSword's code on the internet invites further misuse by other hackers, suggesting a burgeoning market for such exploits.

Official Statements & Responses

An Apple spokesperson emphasized that the vulnerabilities targeted outdated software and that multiple updates have been released to address these issues. They reiterated the importance of keeping devices updated to maintain security. Additionally, Google reported that all malicious domains associated with DarkSword have been blocked by Apple Safe Browsing in the Safari web browser.

Criticism & Opposition

Experts have raised concerns about the implications of these hacking tools being used in mass attacks, suggesting a shift in how state-sponsored and cybercriminal operations are conducted. Cole remarked on the unusual operational security lapses exhibited by the attackers, indicating a lack of caution that could lead to further exposure of such tools.

Conflicting Reports & Gaps

While researchers have identified the DarkSword exploit and its potential impact, the exact number of devices affected remains uncertain. Estimates vary, with some sources suggesting that a significant portion of iPhones are still vulnerable due to users not installing updates. The full extent of the exploit's reach and the motivations behind its deployment are still under investigation.

What's Next

As the cybersecurity landscape evolves, experts recommend that users, particularly in Ukraine, take immediate steps to secure their devices. This includes updating to the latest iOS version, enabling automatic updates, and exercising caution with unknown links and prompts. The ongoing threat posed by DarkSword and similar exploits underscores the need for heightened vigilance in mobile security practices.