As cited
Copy frozen at (site build).
threat intel
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
Google Threat Intelligence Group identified a new iOS exploit chain called DarkSword that leverages six zero-day vulnerabilities to fully compromise devices running iOS 18.4 through 18.7. Since November 2025, multiple commercial surveillance vendors and suspected state-sponsored actors, including the Russian group UNC6353, have deployed DarkSword in campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Apple patched all vulnerabilities by iOS 26.3, and Google has added related delivery domains to Safe Browsing.
Why it matters: Organizations supporting users in targeted regions should prioritize iOS updates to 26.3 or enable Lockdown Mode immediately, as this active exploit chain affects current iOS versions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
Google Threat Intelligence Group identified a new iOS exploit chain called DarkSword that leverages six zero-day vulnerabilities to fully compromise devices running iOS 18.4 through 18.7. Since November 2025, multiple commercial surveillance vendors and suspected state-sponsored actors, including the Russian group UNC6353, have deployed DarkSword in campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Apple patched all vulnerabilities by iOS 26.3, and Google has added related delivery domains to Safe Browsing.
Why it matters: Organizations supporting users in targeted regions should prioritize iOS updates to 26.3 or enable Lockdown Mode immediately, as this active exploit chain affects current iOS versions.
- Source published
- First seen by Cybersecurity Tracker