Apple Patches Critical DarkSword Exploit in iOS 17.5.1 and iPadOS 17.5.1
Key Takeaways Apple has significantly expanded the distribution of iOS 18.7.7 and iPadOS 18.7.7. The update delivers critical backported security patches to millions of devices still running iOS 18....
Key Takeaways
- Apple has significantly expanded the distribution of iOS 18.7.7 and iPadOS 18.7.7.
- The update delivers critical backported security patches to millions of devices still running iOS 18.
- The primary threat addressed is DarkSword, a sophisticated, web-delivered exploit chain capable of extensive data theft.
- DarkSword targets iOS 18.4 through 18.7, leveraging multiple vulnerabilities for kernel-level code execution.
- Users are urged to update immediately, and Apple recommends upgrading to iOS 26.3 or later for comprehensive protection.
Apple Broadens Security Update to Combat DarkSword Exploit
Apple has taken an unprecedented step by widening the rollout of iOS 18.7.7 and iPadOS 18.7.7, pushing essential, backported security updates to a vast number of devices. This move, initiated on April 1, 2026, aims to protect millions of users still operating on iOS 18 from the advanced DarkSword exploit chain, which facilitates the silent exfiltration of sensitive user data via web-based attacks.
Table Of Content
The DarkSword exploit kit is a fully weaponized tool, first detected in active operations as early as November 2025. Its discovery was a collaborative effort by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout, highlighting its significant threat level.

Specifically, DarkSword targets devices running iOS versions 18.4 through 18.7. It achieves full kernel-level code execution without any user interaction beyond a single website visit, exploiting a sophisticated chain of six distinct vulnerabilities across various components, including JavaScriptCore, dyld, and the iOS sandbox.
Upon successful deployment, DarkSword can rapidly steal a wide array of personal information, including passwords, messages, browser history, location data, cryptocurrency wallet contents, and even Apple Health data. The exploit is designed to erase its traces within seconds of operation.
The threat landscape surrounding DarkSword escalated in March 2026 when the toolkit was publicly leaked on GitHub. This leak dramatically lowered the technical barrier for less sophisticated threat actors to leverage the exploit. Prior to the leak, commercial surveillance vendors and suspected state-sponsored entities had already deployed DarkSword against targets in nations such as Saudi Arabia, Turkey, Malaysia, and Ukraine.
Apple’s Rare Backporting Decision
Initially released on March 24, 2026, iOS 18.7.7’s availability was expanded by Apple on April 1, 2026, explicitly to counter the DarkSword threat. This decision represents an unusual policy shift for Apple, which typically requires users to upgrade to the latest major iOS release to receive security updates. The company confirmed that the core DarkSword patches were originally implemented in 2025 but are now being backported to safeguard the approximately 20% of its user base still running iOS 18.
The update addresses over 20 vulnerabilities across critical system components:
- 802.1X (CVE-2026-28865): An authentication flaw that could allow privileged network attackers to intercept traffic. This was fixed through improved state management and was discovered by Héloïse Gollier and Mathy Vanhoef of KU Leuven.
- Kernel (CVE-2026-20687): A use-after-free bug reported by Johnny Franks (@zeroxjf), enabling apps to cause unexpected system termination or write to kernel memory.
- Kernel (CVE-2026-28867 / CVE-2026-28868): Two separate flaws leading to the leakage of sensitive kernel state and kernel memory, discovered by Jian Lee (@speedyfriend433) and Lee Dong Ha of BoB 0xB6.
- Security Framework (CVE-2026-28864): A permissions flaw reported by Alex Radocea, granting local attackers access to Keychain items.
- WebKit (CVE-2026-28861, CVE-2026-20643, CVE-2026-20665, CVE-2026-28871): Multiple browser-engine vulnerabilities that could enable cross-site scripting, Same Origin Policy bypass, Content Security Policy evasion, and cross-origin script handler access via maliciously crafted web content.
- AppleKeyStore (CVE-2026-20637): A use-after-free flaw that could lead to unexpected system termination.
- CoreMedia (CVE-2026-20690): An out-of-bounds access bug triggered by malicious audio streams in media files, found by Hossein Lotfi of Trend Micro Zero Day Initiative.
- iTunes Store (CVE-2025-43534): A path handling flaw allowing physical-access bypass of Activation Lock.
- curl (CVE-2025-14524): An open-source vulnerability causing unintended transmission of sensitive data over incorrect connections.
This critical update is applicable to a broad spectrum of devices, encompassing iPhone XR through iPhone 16e, and various iPad models, from the 5th-generation iPad mini to iPad Pro M4. Users with Automatic Updates enabled will receive iOS 18.7.7 automatically.
Apple has also confirmed that its Lockdown Mode feature offers protection against DarkSword for high-risk individuals requiring enhanced security measures. For the most robust, long-term defense, Apple continues to advise users to upgrade to iOS 26.3 or later, where all vulnerabilities related to DarkSword have been fully remediated.
What You Should Do
- Update Immediately: Ensure your iPhone or iPad is updated to iOS 18.7.7 or iPadOS 18.7.7 without delay. Go to Settings > General > Software Update.
- Enable Automatic Updates: To ensure timely receipt of future patches, verify that Automatic Updates are enabled on your device.
- Consider Upgrading: For the most comprehensive protection against DarkSword and future threats, Apple strongly recommends upgrading to iOS 26.3 or a later version.
- Utilize Lockdown Mode: If you are a high-risk individual (e.g., journalist, activist, government official), enable Apple’s Lockdown Mode for enhanced device hardening.
- Exercise Caution Online: Be wary of suspicious links or websites, as DarkSword is a web-delivered exploit.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.