Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilityproof-of-concept-releasewidely-deployed-product-advisory

DarkSword iPhone Exploit Chain Drives Mass Hacking Risk and Emergency Apple Patches

Updated 29d agoFirst seen May 25, 20267 sources

Security researchers and media reports say the DarkSword iOS exploitation tool has moved from a targeted threat to a broader operational risk, with evidence that attackers can compromise hundreds of millions of iPhones and that exploit code has leaked publicly. Reporting from WIRED, Lookout, iVerify, and AppleInsider describes DarkSword as a powerful zero-click attack capability seen in the wild, raising concern that well-resourced espionage-style techniques are becoming more accessible to additional threat actors.

Apple responded by issuing and then expanding protections, including rare backported patches for older supported devices to shield users who had not yet moved to newer iOS releases. iVerify said its investigations uncovered signs of zero-click mobile exploitation in the United States and warned that mass iOS attacks now represent a serious enterprise risk, while public reporting stressed that organizations and consumers should update affected iPhones immediately as leaked exploit code increases the likelihood of wider abuse.

Share:
DarkSword iPhone Exploit Chain Drives Mass Hacking Risk and Emergency Apple Patches
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 24, 20261mo ago

Exploit code for the severe iOS hack is reported to have leaked publicly

AppleInsider reported that code for the severe iOS hacking technique had leaked broadly, increasing the risk that more attackers could weaponize it. The report framed the situation as leaving users little time to update affected devices.

May 23, 20261mo ago

iVerify warns DarkSword-style mass iOS attacks are a widespread business risk

iVerify published analysis saying the new DarkSword exploit confirms that mass exploitation of iPhones has become a serious enterprise risk, emphasizing broader operational and business impact. This marked a technical and strategic escalation in public understanding of the threat.

iVerify reports zero-click mobile exploitation evidence in the US

iVerify disclosed evidence of zero-click mobile exploitation affecting users in the United States, indicating that advanced mobile attacks were not limited to isolated overseas targeting. The findings added broader victimology and geographic scope to the DarkSword-era threat picture.

Mar 31, 20263mo ago

Apple announces rare backported patches for older iOS 18 devices

Apple said it would ship unusual backported fixes so users on older iOS 18-supported devices would also receive protection from the DarkSword hacking tool. This expanded mitigation beyond the newest OS branch.

Mar 18, 20263mo ago

Apple releases security updates to address the DarkSword exploit

Following reports of DarkSword exploitation, Apple issued iOS security updates to fix the underlying vulnerabilities affecting supported devices. The updates were presented as urgent because the exploit chain could be used against large numbers of iPhones.

Lookout identifies DarkSword iOS exploitation in the wild

Lookout reported that attackers were using the DarkSword hacking tool against iPhone users, establishing that the exploit chain was active in real-world attacks. Wired and other later coverage describe the same in-the-wild discovery rather than a separate event.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

DarkSword iPhone Exploit Chain Drives Mass Hacking Risk and Emergency Apple Patches | Mallory