PSA Hackers can raid iOS 18 with an infected link The Verge
pPosts from this topic will be added to your daily email digest and your homepage feedppSee All TechppPosts from this topic will be added to your daily email digest and your homepage feedppSee All NewsppPosts from this topic will be added to your daily email digest and your homepage feedppSee All AppleppThe DarkSword attack technique can covertly steal messages contacts saved credentials cryptocurrency wallets and more on iPhones running iOS 184 to 1862ppThe DarkSword attack technique can covertly steal messages contacts saved credentials cryptocurrency wallets and more on iPhones running iOS 184 to 1862ppPosts from this author will be added to your daily email digest and your homepage feedppSee All by Emma RothppIf you buy something from a Verge link Vox Media may earn a commission See our ethics statementppPosts from this author will be added to your daily email digest and your homepage feedppSee All by Emma RothppIf youve been putting off an update to iOS 26 now might be the time to do it On Wednesday security researchers published findings on a new hacking tool that targets iPhones running iOS 184 to 1862 as reported earlier by Wired The DarkSword exploit allows bad actors to scoop up the personal information on iPhones that visit malicious links and has already been used by Russian hackersppThe Google Threat Intelligence Group worked with the cybersecurity firms Lookout and iVerify to analyze the attack which could affect up to 270 million devices still running the impacted versions of iOS 18 When a user accesses a compromised website Google says DarkSword uses six different vulnerabilities to carry out an attack targeting Safari giving bad actors the ability to collect text messages contacts saved credentials iCloud files photos cryptocurrency wallets call logs location history and moreppGoogle says it reported the vulnerability to Apple in late 2025 In an emailed statement to The Verge Apple spokesperson Sarah ORourke confirmed that Apple had patched all underlying vulnerabilities in iOS last year before issuing an emergency software update last week for older devices that were unable to update to more recent versions of iOSppDarkSword uses a hitandrun design that allows attackers to extract highvalue data and disappear before traditional detection methods can respond according to Lookout Google says suspected Russian statesponsored hackers used DarkSword to target users in Ukraine Saudi Arabia Malaysia and Turkey These hackers were also discovered using an iOS exploit kit called Coruna which Google highlighted in a report earlier this month iVerify notes that the Russialinked hackers left the DarkSword code unobfuscated unprotected and easily accessible making it easy for other bad actors to access and potentially redeployppGoogle Lookout and iVerify found that the attack doesnt impact users in Lockdown Mode an extreme security feature for the iPhone that protects journalists activists and politicians from targeted attacks Apple and Google have also blocked the malicious links used in DarkSword attacks in Safari and ChromeppKeeping software up to date remains the single most important thing users can do to maintain the high security of their Apple devices as these updates include the latest security fixes and protections ORourke saysppPosts from this author will be added to your daily email digest and your homepage feedppSee All by Emma RothppPosts from this topic will be added to your daily email digest and your homepage feedppSee All AppleppPosts from this topic will be added to your daily email digest and your homepage feedppSee All iOSppPosts from this topic will be added to your daily email digest and your homepage feedppSee All NewsppPosts from this topic will be added to your daily email digest and your homepage feedppSee All SecurityppPosts from this topic will be added to your daily email digest and your homepage feedppSee All TechppA free daily digest of the news that matters mostppThis is the title for the native adppThis is the title for the native adpp 2026 Vox Media LLC All Rights Reservedp