ZeroHour
Security Affairspublished ()ingested @securityaffairs

DarkSword emerges as powerful iOS exploit tool in global attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-14174
Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera

Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet.

Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations.

8.822% KEV
  • Google Chromium (ANGLE component)
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users)
CVE-2025-31277
Buffer Overflow in Apple WebKit (Safari, iOS/iPadOS, macOS, WebKitGTK, WPE)

CVE-2025-31277 is a memory-handling flaw (buffer overflow, CWE-119/CWE-120) in Apple's WebKit engine, the component that renders web content in Safari and in webviews across Apple platforms. It is triggered when a user processes maliciously crafted web content, typically by visiting an attacker-controlled page, causing memory corruption that can compromise the rendering process, with CVSS 3.1 scoring high impact to confidentiality, integrity and availability (8.8) via a network vector requiring user interaction but no privileges. Everyone running WebKit is affected: Safari users and devices on iOS/iPadOS, macOS Sequoia, tvOS, visionOS and watchOS prior to the fixed releases, plus Linux users of WebKitGTK and WPE WebKit as shipped with Red Hat Enterprise Linux (including the AUS and ELS channels). Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2026-03-20 (ransomware linkage unknown) with a BOD 22-01 remediation deadline of 2026-04-03, and contemporaneous reporting describes 'DarkSword', an iOS exploit kit chaining multiple Apple flaws, reportedly including zero-days, in global attacks, possibly including this bug. No public proof-of-concept is known, and fixes shipped in Safari 18.6, iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6.

Do: Upgrade Safari to 18.6 or later and apply the corresponding OS updates: iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6 and watchOS 11.6; on Red Hat Enterprise Linux (including AUS/ELS) install Red Hat's updated WebKitGTK/WPE WebKit packages. Organizations subject to CISA BOD 22-01 must patch or mitigate by the April 3, 2026 deadline. Until patched, restrict WebKit-based browsing and webviews on affected devices to trusted content, since exploitation requires loading maliciously crafted web content.

8.82% KEV
  • Apple Safari all versions prior to 18.6 (fixed in 18.6)
  • Apple iOS / iPhone OS all versions prior to 18.6 (fixed in 18.6)
  • Apple iPadOS all versions prior to 18.6 (fixed in 18.6)
  • +7 more
mass≈1 billion+ users/devices (WebKit ships on essentially every active iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro; the RHEL WebKitGTK/WPE WebKit…
CVE-2025-43510
+1 in the same advisory: …43520
Improper Locking Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVE-2025-43510 is an improper locking flaw (CWE-667) in Apple's operating systems that leads to memory corruption, addressed by improved lock state checking. It is triggered locally: a malicious application already running on the device can cause unexpected changes in memory shared between processes, with the CVSS vector (AV:L, UI:R) indicating user interaction is required but no privileges needed beforehand. Successful exploitation could corrupt or expose cross-process shared memory, yielding high impacts on confidentiality, integrity, and availability (CVSS 3.1 score 7.8), and such shared-memory corruption bugs in Apple's OSes are commonly leveraged as steps in chained attacks such as sandbox escapes. All users of iOS, iPadOS, macOS (Sonoma, Sequoia, and Tahoe branches), tvOS, visionOS, and watchOS on versions earlier than the fixed releases are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-20 with a federal patching deadline of April 3, 2026, and news reports describe an active iOS exploit kit ('DarkSword') using multiple Apple flaws, including zero-days, in global attacks.

Do: Update to the fixed releases: iOS/iPadOS 18.7.2 or iOS/iPadOS 26.1; macOS Sonoma 14.8.2, Sequoia 15.7.2, or Tahoe 26.1; tvOS 26.1; visionOS 26.1; and watchOS 26.1. As a local attack vector, prioritize patching devices that install untrusted apps, and federal agencies must apply the fixes under BOD 22-01 by April 3, 2026 per the CISA KEV listing. Given reports of the DarkSword iOS exploit kit chaining multiple Apple flaws in active attacks, treat unpatched iPhones and iPads as high priority and verify OS versions across your fleet.

7.8
group max
<1% KEV
  • Apple iPhone OS (iOS) All versions prior to iOS 18.7.2 and prior to iOS 26.1
  • Apple iPadOS All versions prior to iPadOS 18.7.2 and prior to iPadOS 26.1
  • Apple macOS macOS Sonoma prior to 14.8.2; macOS Sequoia prior to 15.7.2; macOS Tahoe prior to 26.1
  • +3 more
mass>1 billion active Apple devices across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS (essentially the entire unpatched active install base)
CVE-2025-43529
Use-After-Free in Apple WebKit (Safari, iOS, macOS) Allows Arbitrary Code Execution

CVE-2025-43529 is a use-after-free (CWE-416) flaw in Apple's WebKit browser engine, fixed via improved memory management. It is triggered when a device processes maliciously crafted web content, and successful exploitation can lead to arbitrary code execution with network reachability and no privileges required (CVSS 3.1: 8.8, user interaction needed). It affects a broad range of Apple products: Safari, iPhone OS/iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, with fixes delivered in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Apple reports the issue was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-15 (a companion CVE-2025-14174 was issued for the same report). No public proof-of-concept is known, and EPSS assigns an 8.9% probability of exploitation within 30 days (95th percentile).

Do: Update affected devices to Safari 26.2, iOS/iPadOS 26.2 (or iOS/iPadOS 18.7.3 on devices that remain on the iOS 18 branch), macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2, prioritizing mobile users and high-risk targeted individuals. Federal agencies must remediate per CISA BOD 22-01 requirements since the CVE is in the KEV catalog (added 2025-12-15); also review the related CVE-2025-14174 addressed by the same updates. Check device fleet inventory for WebKit-exposed Apple hardware that cannot reach the fixed versions and confirm patches have been applied.

8.89% KEV
  • Apple Safari All versions prior to Safari 26.2
  • Apple iPhone OS (iOS) Versions prior to iOS 26.2 (legacy branch fixed in iOS 18.7.3)
  • Apple iPadOS Versions prior to iPadOS 26.2 (legacy branch fixed in iPadOS 18.7.3)
  • +4 more
masswell over 1 billion Apple devices/users across iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro running pre-26.2 (or pre-18.7.3 legacy) software
CVE-2026-20700
Exploited Memory Corruption Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVE-2026-20700 is a memory corruption (buffer overflow) issue in multiple Apple operating systems that Apple addressed through improved state management. The flaw requires a local attack vector: an attacker who already has some memory-write capability on the device — typically obtained via a chained exploit such as a browser or sandbox escape — can leverage this bug to execute arbitrary code. Attackers gain code execution with the privileges of the compromised component, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 (High) score. All users of iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch running versions earlier than the 26.3 updates are affected. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-12; related CVEs CVE-2025-14174 and CVE-2025-43529 were issued from the same report.

Do: Update all Apple devices to iOS/iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3 or later; the fix also addresses related CVE-2025-14174 and CVE-2025-43529 from the same report. Federal agencies must meet the KEV/BOD 22-01 deadline by patching per vendor instructions or discontinuing affected device use. Given the targeted, exploit-kit-driven attacks (e.g., DarkSword/Coruna tooling reported in the wild), prioritize updates for high-risk users such as executives, journalists, and activists, and verify fleet-wide OS versions rather than assuming patch compliance.

7.81% KEV
  • Apple iOS (iPhone OS) all versions prior to iOS 26.3
  • Apple iPadOS all versions prior to iPadOS 26.3
  • Apple macOS (Tahoe) all versions prior to macOS Tahoe 26.3
  • +3 more
mass≈1.5–2 billion active Apple devices (Apple's publicly reported active install base), with a large share likely on pre-26.3 versions
Full article895 words · extracted from securityaffairs.com · click to collapse

DarkSword, a new iOS exploit kit, is used by multiple actors to steal data in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine.

Lookout Threat Labs discovered a new iOS exploit kit called DarkSword that has been used since late 2025 by multiple threat actors, including surveillance vendors and likely nation-state actors. The toolkit enables full-chain attacks to steal sensitive data from Apple devices and has been observed in campaigns targeting countries such as Saudi Arabia, Turkey, Malaysia, and Ukraine.

The exploit chain relies on six vulnerabilities, three used as zero-days, to achieve full device compromise:

  • CVE-2025-31277 – JavaScriptCore memory corruption (CVSS: 8.8)
  • CVE-2026-20700 – dyld PAC bypass (CVSS: 8.6) (zero-day)
  • CVE-2025-43529 – JavaScriptCore memory corruption (CVSS: 8.8) (zero-day)
  • CVE-2025-14174 – ANGLE memory corruption (CVSS: 8.8) (zero-day)
  • CVE-2025-43510 – iOS kernel memory issue (CVSS: 8.6)
  • CVE-2025-43520 – iOS kernel memory corruption (CVSS: 8.6)

Together, these flaws enable full-chain exploitation and complete control of targeted iOS devices.

DarkSword targets iPhones running iOS 18.4–18.7 and has been used by the suspected Russian-linked group UNC6353 against Ukrainian targets. It allows attackers to steal sensitive data, including credentials and crypto wallet information, then quickly exfiltrates it in a “hit-and-run” approach before cleaning traces.

The exploits appear to be linked to Coruna exploits, DarkSword enables near full device access with minimal user interaction, showing how advanced exploits are now available on a secondary market to a wider range of threat actors.

“DarkSword aims to extract an extensive set of personal information including credentials from the device and specifically targets a plethora of crypto wallet apps, hinting at a financially motivated threat actor.” reads the report published by Lookout. “Notably, DarkSword appears to take a “hit-and-run” approach by collecting and exfiltrating the targeted data from the device within seconds or at most minutes followed by cleanup.”

Researchers investigating Coruna uncovered related infrastructure linked to Russian actor UNC6353, including a similar domain used in attacks on compromised Ukrainian sites, even government ones. Malicious iframes loaded scripts to fingerprint devices and target specific iOS versions. Further analysis revealed a new exploit chain, later named DarkSword, discovered in late 2025 through joint research by Lookout, iVerify, and Google, confirming a distinct and evolving threat.

While it initially appeared that this may be another site distributing Coruna, upon closer inspection of the our researchers found that the iframe loads a javascript file called rce_loader.js, which is largely responsible for fingerprinting devices visiting the compromised site in order to determine whether to route the devices to the iOS exploit chain. However, the script was looking for iOS devices with OS versions 18.4 or 18.6.2, which are iOS versions that are not susceptible to the exploit chains used in Coruna.

darksword exploit
An excerpt from rce_loader.js showing that devices with specific iOS versions are routed to different scripts for exploitation based on the version. – Source Lookout report

Recognizing that this was a new threat, our researchers analyzed the code and began capturing all of the stages of the exploits. 

“As opposed to many other previously reported cases of sophisticated attacks on mobile devices, DarkSword is not designed for ongoing surveillance.” states the report. “Once it finishes collecting and exfiltrating the targeted data, it deletes the files it created on the filesystem of the device and exits. Its dwell time on the device is likely in the range of minutes, depending on the amount of data it discovers and exfiltrates.”

According to Lookout, the actor behind the exploit, UNC6353, remains a largely unknown group but has used advanced iOS exploit chains in watering hole attacks on Ukrainian websites. Likely well-funded, it appears to rely on third-party or brokered exploits, possibly linked to Russian ecosystems. The group targets both intelligence and financial data, including crypto assets, suggesting dual motives.

Its infrastructure is limited but shows deep access to compromised sites. Poor obfuscation and signs of AI-assisted code suggest limited in-house expertise. Overall, UNC6353 is assessed as a capable yet not highly sophisticated actor, potentially a Russia-aligned proxy blending espionage with cybercrime.

DarkSword shows a troubling trend: advanced iOS exploit chains are being sold on a secondary market, letting even less skilled actors launch powerful attacks. These near zero-click watering hole campaigns are stealthy and bypass user awareness. Once infected, devices face full compromise, with risks to both personal and corporate data, highlighting the urgent need for faster patching and stronger mobile defenses.

“The discovery of DarkSword as the second iOS exploit chain found in the hands of this at least partially financially motivated threat actor reveals a worrying trend.” concludes the report. “There appears to be a secondary market for technically sophisticated exploit chains in which unscrupulous sellers are willing to serve buyers with little or no concerns for how they are going to be used. These groups can then easily customize these kits into malware for their specific purposes, possibly with the help of AI.”

Google GTIG experts found multiple actors using DarkSword since November 2025, and believes other surveillance vendors or threat groups are likely using the exploit chain as well.

“The use of both DarkSword and Coruna by a variety of actors demonstrates the ongoing risk of exploit proliferation across actors of varying geography and motivation.” concludes GTIG.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, DarkSword)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/189662/hacking/darksword-emerges-as-powerful-ios-exploit-tool-in-global-attacks.html