CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 320

As cited

Copy frozen at (site build).

threat intel

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

Google Threat Intelligence Group identified a new iOS exploit chain called DarkSword that leverages six zero-day vulnerabilities to fully compromise devices running iOS 18.4 through 18.7. Since November 2025, multiple commercial surveillance vendors and suspected state-sponsored actors, including the Russian group UNC6353, have deployed DarkSword in campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Apple patched all vulnerabilities by iOS 26.3, and Google has added related delivery domains to Safe Browsing.

Why it matters: Organizations supporting users in targeted regions should prioritize iOS updates to 26.3 or enable Lockdown Mode immediately, as this active exploit chain affects current iOS versions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

Google Threat Intelligence Group identified a new iOS exploit chain called DarkSword that leverages six zero-day vulnerabilities to fully compromise devices running iOS 18.4 through 18.7. Since November 2025, multiple commercial surveillance vendors and suspected state-sponsored actors, including the Russian group UNC6353, have deployed DarkSword in campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Apple patched all vulnerabilities by iOS 26.3, and Google has added related delivery domains to Safe Browsing.

Why it matters: Organizations supporting users in targeted regions should prioritize iOS updates to 26.3 or enable Lockdown Mode immediately, as this active exploit chain affects current iOS versions.

VendorsAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary