DarkSword Exploit Chain That Can Hack Millions of iPhones Leaked Online
DarkSword is an iOS exploit toolkit that has recently been leaked on GitHub, significantly increasing the risk for devices running outdated software. Originally a sophisticated tool used in targeted attacks, it is now accessible for broader use.
DarkSword is an iOS exploit toolkit that has recently been leaked on GitHub, significantly increasing the risk for devices running outdated software. Originally a sophisticated tool used in targeted attacks, it is now accessible for broader use.
DarkSword is a comprehensive iOS exploit chain developed using JavaScript. Initially discovered in March 2026 by Google’s Threat Intelligence Group, it combines six zero-day vulnerabilities for complete device compromise upon visiting a malicious website.
CVE Exploit Module Vulnerability Type Zero-Day Patched In
CVE-2025-31277 rce_module.js JIT optimization / type confusion No iOS 18.6
CVE-2025-43529 rce_worker_18.6.js , rce_worker_18.7.js Use-after-free / garbage collection bug Yes iOS 18.7.3, 26.2
DarkSword is an iOS exploit toolkit that has recently been leaked on GitHub, significantly increasing the risk for devices running outdated software.
CVE-2026-20700 rce_worker_18.4.js , rce_worker_18.6.js , rce_worker_18.7.js Memory corruption / user-mode PAC bypass Yes iOS 26.3
CVE-2025-14174 sbox0_main_18.4.js , sbx0_main.js Out-of-bounds memory access Yes iOS 18.7.3, 26.2
CVE-2025-43510 sbx1_main.js Memory management / copy-on-write bug No iOS 18.7.2, 26.1
CVE-2025-43520 pe_main.js Kernel-mode race condition No iOS 18.7.2, 26.1
The exploit chain starts when Safari loads a malicious iframe, breaking out of the WebContent sandbox to inject code into the mediaplaybackd process, achieving full kernel access. This access allows modification of sandbox restrictions without physical device access.
DarkSword has been used in espionage, targeting Ukrainian citizens by a group known as UNC6353. The toolkit facilitates data extraction including passwords and messages. It is now available online, making it deployable on malicious servers quickly.
Security experts advise updating to iOS 26 or applying emergency patches to mitigate risks. Devices with Lockdown Mode enabled are protected from DarkSword attacks. Immediate updates are recommended for users on iOS 18 or earlier versions.
Based on reporting by Cyber Security News.
