Technology & Science
Leaked 'DarkSword' iOS Exploit Kit Escapes State Control, Triggers Apple’s First Background Security Patch
The formerly state-grade DarkSword exploit chain—six linked flaws targeting iOS 18.4-18.7—has now surfaced in large-scale watering-hole attacks by multiple groups, forcing Apple to rush an out-of-band iOS 26.3.1(a) patch on 17 March 2026.
Focusing Facts
- Google, Lookout and iVerify report DarkSword combines six CVEs (three zero-days) to achieve full device takeover via Safari/WebGPU, first observed in-the-wild attacks November 2025.
- iVerify estimates 220–270 million iPhones—about 14–24 % of active devices—remain on vulnerable iOS 18 builds.
- Apple’s 17 Mar 2026 release of iOS 26.3.1(a) marked its inaugural use of the new “Background Security Improvement” mechanism to hot-patch WebKit flaws.
See how 3 sources reported this story.
- ✓ Full multi-perspective analysis on every story
- ✓ Primary source links for every claim
- ✓ Daily email briefing — no algorithm
Perspectives in this article
- General consumer news outlets
- Cybersecurity research-focused tech media
- Apple-sympathetic business/tech press