June 2, 2026

PBX Science

VoIP & PBX, Networking, DIY, Computers.

Apple Pushes Rare iOS 18 Security Update to Block the DarkSword Exploit Kit

Apple Pushes Rare iOS 18 Security Update to Block the DarkSword Exploit Kit



Apple Expands iOS 18.7.7 to Block DarkSword Exploit Kit
The Security Dispatch Independent coverage of cybersecurity & technology

Apple Pushes Rare iOS 18 Security Update to Block the DarkSword Exploit Kit

In an unusual departure from its update policy, Apple has expanded iOS 18.7.7 and iPadOS 18.7.7 to millions of additional devices — shielding users who have yet to migrate to iOS 26 from a sophisticated, state-sponsored exploit chain active since mid-2025.

Breaking April 3, 2026 · Security & Privacy · 8 min read
⚠️
Action recommended: If your iPhone or iPad is running any version of iOS 18 prior to 18.7.7, install the update immediately via Settings → General → Software Update. The vulnerabilities patched by this update are known to be actively exploited in the wild.

Apple on April 1, 2026, made iOS 18.7.7 and iPadOS 18.7.7 available to a dramatically wider range of iPhones and iPads, protecting users from a dangerous web-based attack toolkit known as DarkSword. The move is remarkable because Apple rarely backports security patches to users of an older iOS generation who could technically upgrade to the current major release — in this case, iOS 26.

“We enabled the availability of iOS 18.7.7 for more devices on April 1, 2026, so users with Automatic Updates turned on can automatically receive important security protections from web attacks called DarkSword,” an Apple spokesperson said. “The fixes associated with the DarkSword exploit first shipped in 2025.”

A Timeline of the Response

July 2025
DarkSword exploit kit first observed in campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine, according to Google Threat Intelligence Group (GTIG), iVerify, and Lookout.
November 2025 onward
Exploitation activity intensifies. The chain begins appearing in campaigns linked to both commercial spyware vendors and state-sponsored actors.
March 2026
Apple releases iOS 15.8.7, iOS 16.7.15, and iPadOS equivalents to patch DarkSword-related vulnerabilities on older devices unable to run iOS 18.
March 24, 2026
Apple releases iOS 18.7.7 (build 22H333) and iPadOS 18.7.7, initially limited to the iPhone XS, iPhone XS Max, iPhone XR, and the 7th-generation iPad — devices incapable of running iOS 26.
April 1, 2026
Apple expands iOS 18.7.7 (build 22H340) to all remaining iPhones and iPads still on iOS 18, including those fully capable of upgrading to iOS 26. A newer source code of the kit is leaked to GitHub, amplifying urgency.

What Is DarkSword?

DarkSword is a full-chain iOS exploit kit, meaning it links multiple individual vulnerabilities into a seamless attack sequence capable of fully compromising a target device. Detailed technical analysis was published by Google Threat Intelligence Group (GTIG), iVerify, and Lookout — the organizations that first disclosed the toolkit publicly.

DarkSword — Six-Vulnerability Exploit Chain
01WebKit — initial remote code execution via malicious web content
02WebKit — sandbox escape escalation
03Safari — browser-level privilege bypass
04Safari — cross-origin data exposure
05Dynamic loader — library injection for persistence
06Kernel — root-level privilege escalation and full device takeover

Critically, the attack requires no interaction from the victim beyond visiting a legitimate-but-compromised website or loading a malicious advertisement inside Safari. This “drive-by” or “watering hole” delivery model makes DarkSword particularly dangerous: there is nothing unusual for a user to notice, click, or approve. Once triggered on a vulnerable device (those running iOS 18.4 through 18.7), attackers can deploy backdoors and data-mining tools for persistent access and information theft.

The kit has since been partially leaked on GitHub, raising concerns that less sophisticated threat actors could adapt and deploy it, substantially broadening the threat landscape beyond the state-sponsored groups initially linked to the attacks.

Just loading a compromised site or even a malicious advertisement inside Safari is enough to trigger the exploit chain if your device is still missing the relevant patches.

— Malwarebytes Security Research, April 2026

Targeted Countries and Victims

Researchers at GTIG, iVerify, and Lookout identified victims primarily in four countries. Apple’s own Lockdown Mode has been recommended as an additional layer of protection for high-risk individuals.

🇸🇦 Saudi Arabia 🇹🇷 Turkey 🇲🇾 Malaysia 🇺🇦 Ukraine

Devices Now Covered by iOS 18.7.7

Following Apple’s April 1 expansion, the following devices can now receive iOS 18.7.7 or iPadOS 18.7.7 as a security-only update, without needing to upgrade to iOS 26:

Supported Devices — iOS / iPadOS 18.7.7 Full list

iPhone

  • iPhone XR
  • iPhone XS & XS Max
  • iPhone 11 (all models)
  • iPhone SE (2nd generation)
  • iPhone 12 (all models)
  • iPhone 13 (all models)
  • iPhone SE (3rd generation)
  • iPhone 14 (all models)
  • iPhone 15 (all models)
  • iPhone 16 (all models)
  • iPhone 16e

iPad

  • iPad (7th generation, A16)
  • iPad mini (5th generation, A17 Pro)
  • iPad Air (3rd – 5th generation)
  • iPad Air 11-inch (M2 – M3)
  • iPad Air 13-inch (M2 – M3)
  • iPad Pro 11-inch (1st gen – M4)
  • iPad Pro 12.9-inch (3rd – 6th gen)
  • iPad Pro 13-inch (M4)

Why This Update Is Unusual

Apple’s standard policy has been to only provide security updates for the current generation of its operating system, using the promise of fixes as leverage to encourage users to upgrade. Extending iOS 18 patches to devices fully capable of running iOS 26 represents a significant — and, according to security professionals, welcome — break from that practice.

Users who do not have auto-updates enabled will see a prominent Critical Security Update alert on their device. Those who wish to stay on iOS 18 can navigate to Settings → General → Software Update, scroll past the featured iOS 26.4 option, and find iOS 18.7.7 listed under an “Also Available” section.

Apple continues to recommend that users migrate to iOS 26 for the most comprehensive security coverage and access to the latest features. However, the company has made clear that user safety takes precedence in this instance.

How to Install the Update

  1. Open Settings and tap General.
  2. Tap Software Update and wait for the page to load.
  3. If your device supports iOS 26, scroll past the highlighted iOS 26 option.
  4. Find the “Also Available” section and tap iOS 18.7.7.
  5. Tap Download and Install to apply the security update without upgrading.
  6. Consider enabling Automatic Updates to receive critical patches automatically in the future.

Apple also notes that Lockdown Mode provides additional protection against this class of web-based attacks for users who require an elevated security posture — such as journalists, activists, and executives who may be at heightened risk of targeted surveillance.

© 2026 The Security Dispatch  ·  All rights reserved  ·  For informational purposes only

Apple Pushes Rare iOS 18 Security Update to Block the DarkSword Exploit Kit

Apple Pushes Rare iOS 18 Security Update to Block the DarkSword Exploit Kit


Windows Software Alternatives in Linux


Disclaimer of pbxscience.com

PBXscience.com © All Copyrights Reserved. | Newsphere by AF themes.