ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

DarkSword: Researchers uncover another iOS exploit kit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-14174
Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera

Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet.

Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations.

8.822% KEV
  • Google Chromium (ANGLE component)
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users)
CVE-2025-31277
Buffer Overflow in Apple WebKit (Safari, iOS/iPadOS, macOS, WebKitGTK, WPE)

CVE-2025-31277 is a memory-handling flaw (buffer overflow, CWE-119/CWE-120) in Apple's WebKit engine, the component that renders web content in Safari and in webviews across Apple platforms. It is triggered when a user processes maliciously crafted web content, typically by visiting an attacker-controlled page, causing memory corruption that can compromise the rendering process, with CVSS 3.1 scoring high impact to confidentiality, integrity and availability (8.8) via a network vector requiring user interaction but no privileges. Everyone running WebKit is affected: Safari users and devices on iOS/iPadOS, macOS Sequoia, tvOS, visionOS and watchOS prior to the fixed releases, plus Linux users of WebKitGTK and WPE WebKit as shipped with Red Hat Enterprise Linux (including the AUS and ELS channels). Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2026-03-20 (ransomware linkage unknown) with a BOD 22-01 remediation deadline of 2026-04-03, and contemporaneous reporting describes 'DarkSword', an iOS exploit kit chaining multiple Apple flaws, reportedly including zero-days, in global attacks, possibly including this bug. No public proof-of-concept is known, and fixes shipped in Safari 18.6, iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6.

Do: Upgrade Safari to 18.6 or later and apply the corresponding OS updates: iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6; on Red Hat Enterprise Linux (including AUS/ELS) install Red Hat's updated WebKitGTK/WPE WebKit packages. Organizations subject to CISA BOD 22-01 must patch or mitigate by the April 3, 2026 deadline. Until patched, restrict WebKit-based browsing and webviews on affected devices to trusted content, since exploitation requires loading maliciously crafted web content.

8.82% KEV
  • Apple Safari all versions prior to 18.6 (fixed in 18.6)
  • Apple iOS / iPhone OS all versions prior to 18.6 (fixed in 18.6)
  • Apple iPadOS all versions prior to 18.6 (fixed in 18.6)
  • +7 more
mass≈1 billion+ users/devices (WebKit ships on essentially every active iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro; the RHEL WebKitGTK/WPE WebKit…
CVE-2025-43510
+1 in the same advisory: …43520
Improper Locking Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVE-2025-43510 is an improper locking flaw (CWE-667) in Apple's operating systems that leads to memory corruption, addressed by improved lock state checking. It is triggered locally: a malicious application already running on the device can cause unexpected changes in memory shared between processes, with the CVSS vector (AV:L, UI:R) indicating user interaction is required but no privileges needed beforehand. Successful exploitation could corrupt or expose cross-process shared memory, yielding high impacts on confidentiality, integrity, and availability (CVSS 3.1 score 7.8), and such shared-memory corruption bugs in Apple's OSes are commonly leveraged as steps in chained attacks such as sandbox escapes. All users of iOS, iPadOS, macOS (Sonoma, Sequoia, and Tahoe branches), tvOS, visionOS, and watchOS on versions earlier than the fixed releases are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-20 with a federal patching deadline of April 3, 2026, and news reports describe an active iOS exploit kit ('DarkSword') using multiple Apple flaws, including zero-days, in global attacks.

Do: Update to the fixed releases: iOS/iPadOS 18.7.2 or iOS/iPadOS 26.1; macOS Sonoma 14.8.2, Sequoia 15.7.2, or Tahoe 26.1; tvOS 26.1; visionOS 26.1; and watchOS 26.1. As a local attack vector, prioritize patching devices that install untrusted apps, and federal agencies must apply the fixes under BOD 22-01 by April 3, 2026 per the CISA KEV listing. Given reports of the DarkSword iOS exploit kit chaining multiple Apple flaws in active attacks, treat unpatched iPhones and iPads as high priority and verify OS versions across your fleet.

7.8
group max
<1% KEV
  • Apple iPhone OS (iOS) All versions prior to iOS 18.7.2 and prior to iOS 26.1
  • Apple iPadOS All versions prior to iPadOS 18.7.2 and prior to iPadOS 26.1
  • Apple macOS macOS Sonoma prior to 14.8.2; macOS Sequoia prior to 15.7.2; macOS Tahoe prior to 26.1
  • +3 more
mass>1 billion active Apple devices across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS (essentially the entire unpatched active install base)
CVE-2025-43529
Use-After-Free in Apple WebKit (Safari, iOS, macOS) Allows Arbitrary Code Execution

CVE-2025-43529 is a use-after-free (CWE-416) flaw in Apple's WebKit browser engine, fixed via improved memory management. It is triggered when a device processes maliciously crafted web content, and successful exploitation can lead to arbitrary code execution with network reachability and no privileges required (CVSS 3.1: 8.8, user interaction needed). It affects a broad range of Apple products: Safari, iPhone OS/iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, with fixes delivered in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Apple reports the issue was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-15 (a companion CVE-2025-14174 was issued for the same report). No public proof-of-concept is known, and EPSS assigns an 8.9% probability of exploitation within 30 days (95th percentile).

Do: Update affected devices to Safari 26.2, iOS/iPadOS 26.2 (or iOS/iPadOS 18.7.3 on devices that remain on the iOS 18 branch), macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2, prioritizing mobile users and high-risk targeted individuals. Federal agencies must remediate per CISA BOD 22-01 requirements since the CVE is in the KEV catalog (added 2025-12-15); also review the related CVE-2025-14174 addressed by the same updates. Check device fleet inventory for WebKit-exposed Apple hardware that cannot reach the fixed versions and confirm patches have been applied.

8.89% KEV
  • Apple Safari All versions prior to Safari 26.2
  • Apple iPhone OS (iOS) Versions prior to iOS 26.2 (legacy branch fixed in iOS 18.7.3)
  • Apple iPadOS Versions prior to iPadOS 26.2 (legacy branch fixed in iPadOS 18.7.3)
  • +4 more
masswell over 1 billion Apple devices/users across iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro running pre-26.2 (or pre-18.7.3 legacy) software
CVE-2026-20700
Exploited Memory Corruption Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVE-2026-20700 is a memory corruption (buffer overflow) issue in multiple Apple operating systems that Apple addressed through improved state management. The flaw requires a local attack vector: an attacker who already has some memory-write capability on the device — typically obtained via a chained exploit such as a browser or sandbox escape — can leverage this bug to execute arbitrary code. Attackers gain code execution with the privileges of the compromised component, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 (High) score. All users of iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch running versions earlier than the 26.3 updates are affected. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-12; related CVEs CVE-2025-14174 and CVE-2025-43529 were issued from the same report.

Do: Update all Apple devices to iOS/iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3 or later; the fix also addresses related CVE-2025-14174 and CVE-2025-43529 from the same report. Federal agencies must meet the KEV/BOD 22-01 deadline by patching per vendor instructions or discontinuing affected device use. Given the targeted, exploit-kit-driven attacks (e.g., DarkSword/Coruna tooling reported in the wild), prioritize updates for high-risk users such as executives, journalists, and activists, and verify fleet-wide OS versions rather than assuming patch compliance.

7.81% KEV
  • Apple iOS (iPhone OS) all versions prior to iOS 26.3
  • Apple iPadOS all versions prior to iPadOS 26.3
  • Apple macOS (Tahoe) all versions prior to macOS Tahoe 26.3
  • +3 more
mass≈1.5–2 billion active Apple devices (Apple's publicly reported active install base), with a large share likely on pre-26.3 versions

Indicators of compromiseAll →

TypeIndicatorContext
domaincdncounter.netrity company Lookout identified another suspicious domain ( cdncounter[.]net ) closely linked to previously known malicious infrastruc
Full article824 words · extracted from helpnetsecurity.com · click to collapse

A powerful iPhone hacking toolkit dubbed “DarkSword” has been used since November 2025 to compromise devices by exploiting zero-day iOS vulnerabilities, Google researchers have shared.

iOS vulnerabilities exploited by DarkSword

Two weeks ago, Google Threat Intelligence Group (GTIG) and iVerify disclosed the existence of Coruna, a spy-grade iOS exploit kit that has been used in a commercial surveillance operation, by state-linked threat actors engaged in cyber espionage, and cybercriminals.

While Coruna contains five full iOS exploit chains and a total of 23 exploits for vulnerabilities (with and without a CVE identifier), Darksword chains six vulnerabilities to allow attackers to achieve remote code execution on vulnerable iPhones and deploy malicious payloads.

Three of these are flaws in WebKit, the browser engine used by Apple’s Safari browser and all web browsers on iOS and iPadOS. Two are in the iOS (and macOS) kernel and one in the Dynamic Link Editor component of Apple’s operating systems.

Apple fixed:

  • CVE-2025-31277 (WebKit) in iOS 18.6, in July 2025
  • CVE-2025-43510 and CVE-2025-43520 (kernel) in iOS 26.1 and 18.7.2, in November 2025
  • CVE-2025-43529 and CVE-2025-14174 (WebKit) in iOS 26.2 and 18.7.3, in December 2025 (after reports of targeted in-the-wild exploitation)
  • CVE-2026-20700 (dyld) in iOS 26.3, in February 2026, also after confirmed zero-day exploitation.

DarkSword discovery

According to Google researchers, DarkSword has been leveraged in a variety of attack campaigns tied to several threat actors, including suspected Russian state-sponsored attackers UNC6353, who also leveraged the Coruna exploit kit, and customers of PARS Defense, a Turkish commercial surveillance vendor.

Timeline of observed DarkSword use and Apple’s patching of the flaws (Source: Google Threat Intelligence Group)

After uncovering Coruna, researchers from mobile security company Lookout identified another suspicious domain (cdncounter[.]net) closely linked to previously known malicious infrastructure tied to UNC6748.

The domain shared technical characteristics with earlier infrastructure and was connected to compromised Ukrainian websites where hidden iframes were used to deliver malicious code.

Further analysis showed this activity was not Coruna but a new operation: the injected code fingerprinted visiting devices and selectively targeted certain iOS versions with a separate exploit chain: DarkSword (named thus to internal references found in the malware).

“DarkSword is a complete exploit chain and infostealer written in JavaScript. It leverages multiple vulnerabilities to establish privileged code execution to access sensitive information and exfiltrate it off the device. The kill chain begins with Safari encountering the malicious iframe embedded in a web page. Once loaded, Darksword breaks out of the WebContent sandbox and then leverages WebGPU to inject into mediaplaybackd. From there it can craft Kernel read/write access, which it leverages to gain access to privileged processes and modify sandbox restrictions, gaining access to restricted parts of the filesystem,” Lookout researchers explained.

After gaining deeper access to the device, the malware runs a main script that coordinates several smaller malicious components, which collect sensitive data like passwords, encryption keys, and files, and store them temporarily on the device, then send them to a remote server controlled by the attackers.

DarkSword use

In November 2025, Google researchers spotted DarkSword being used by UNC6748 to target Saudi Arabian users via a Snapchat-themed website. In November 2025 and January 2026, they uncovered evidence of DarkSword being used in two campaigns associated with different PARS Defense customers and targeting users in Turkey and Malaysia.

UNC6353, who were previously observed using Coruna, also targeted Ukrainian users again with DarkSword and a backdoor (GHOSTBLADE) that collected a wide variety of information about the device, installed apps, accounts, location history, photos, calendar entries, notes, cryptocurrency wallet and account data, Safari history, and more.

iVerify researchers also analyzed that last campaign.

Lookout researchers say UNC6353 appears to have access to advanced iOS exploit chains, likely originating from top-tier commercial surveillance vendors. Some of these exploits were used as zero-days, suggesting the group is well funded and may be linked to exploit brokers such as Matrix LLC / Operation Zero.

They also note that both Coruna and DarkSword can steal cryptocurrency alongside sensitive personal data, meaning they can be used for both espionage and financial theft. It remains unclear whether crypto theft was a primary objective, leaving open the possibility that the group is financially motivated or that this state-aligned actor has expanded into targeting mobile users for profit.

What to do?

The fear now is that other cybercriminals might get their hands on the two toolkits and leverage them to target a larger pool of iOS users.

“The combined attacks now likely affect hundreds of millions of unpatched devices running iOS versions from 13 to 18.6.2,” iVerify researchers noted.

“We strongly recommend updating to iOS 18.7.6 or iOS 26.3.1. This will mitigate all vulnerabilities that have been exploited in these attack chains.”

Google researchers say users that cannot update to either of those should consider enabling Lockdown Mode for enhanced security.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/03/19/darksword-ios-exploit-iphone/