Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DarkSword is a sophisticated iPhone exploit chain and data-stealing malware—not an App Store app. It has been used in campaigns against people in several countries, and it can take advantage of vulnerable iOS versions after a person visits a malicious website. Update your iPhone to the latest iOS version it supports; Apple’s security fixes address the vulnerabilities used by DarkSword.

What DarkSword is—and how it can reach an iPhone

Google Threat Intelligence describes DarkSword as a full-chain iOS exploit: a series of vulnerabilities used to move from a browser compromise toward deeper control of a device. Google says six vulnerabilities have been used across the activity it tracked, and that multiple commercial surveillance vendors and suspected state-sponsored actors have used the toolkit since at least November 2025.

In the disclosed campaigns, the initial lure was a malicious website, sometimes placed where a particular group of people might visit—an approach known as a watering hole. Lookout and iVerify report little or no user interaction in the campaigns they describe. That means the risk is not limited to someone who knowingly installs an app or opens an attachment: on a vulnerable device, visiting a page set up for an exploit may be enough.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The technical path starts in the browser. Google identifies CVE-2025-31277 and CVE-2026-20700 in one early chain; Lookout describes Safari and WebGPU exploitation, and iVerify says the JavaScript exploit chains progressed from WebKit to the kernel. In plain language, the attacker tries to break out of the browser’s normal restrictions and gain access at a deeper level of the operating system.

Where the activity has been reported

Google observed campaigns in Saudi Arabia, Turkey, Malaysia, and Ukraine. It linked a Ukrainian watering-hole campaign to UNC6353, which Google describes as a suspected Russian espionage group, and reported a Snapchat-themed site targeting Saudi Arabian users in activity it attributed to UNC6748. These are source attributions, not proof that a government directed a particular operation.

Which iPhones and iOS versions are exposed?

The campaigns disclosed by the vendors targeted iOS 18.4 through 18.6.2. Google describes support through iOS 18.7, while Lookout recommends iOS 18.7.3 or later, or iOS 26.3 or later, for the affected branches. Google says all the vulnerabilities used by DarkSword were patched by iOS 26.3, with most patched earlier. Because the reports describe different exploit chains and patch stages, do not assume that simply being on iOS 18.7 means your device has every relevant fix.

The practical check is your device’s installed version and whether it can install a later supported release. Open Settings > General > Software Update and install the latest version offered for your iPhone. If no update appears, check again after connecting to Wi-Fi and power; if the phone still cannot receive a patched release, treat it as unprotected against vulnerabilities that its installed software has not fixed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Exposure is not the same as infection

iVerify wrote in 2026 that up to 270 million devices were still running the affected 2025 iOS versions. That is an estimate of devices potentially exposed by their software, not a count of confirmed DarkSword infections. Google, Lookout, and iVerify have not published a confirmed global infection total in the disclosures described here.

What DarkSword can steal

Reports describe collection of data from across the phone, including messages, email, credentials, photos, notes, iCloud files, browser history, Wi-Fi passwords, location and call history, health and calendar data, SIM and cellular information, and cryptocurrency-wallet data. The exact information available can depend on the exploit and what is stored or accessible on the particular device.

Lookout calls the collection approach “hit-and-run”: the malware rapidly exfiltrates valuable data and erases evidence of its presence to reduce the time it can be detected. iVerify reports that the Ukrainian instance was written entirely in JavaScript. A short-lived or erased footprint does not mean data already copied by an attacker has been recovered or deleted.

What to do now

1. Install the latest supported iOS update

Go to Settings > General > Software Update and install the latest release available for your iPhone. Do not delay an offered security update while waiting for a particular version number: Apple’s fixes arrived in stages, and the latest supported release is the clearest way to receive the security corrections available to your model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Use Lockdown Mode if you cannot update or face elevated risk

Google recommends Apple Lockdown Mode when an update cannot be applied. It is also worth considering for people at elevated risk of targeted surveillance, such as journalists, activists, public officials, executives, and others whose work or public profile could make them a target. Find it under Settings > Privacy & Security > Lockdown Mode. Lockdown Mode is a protective measure, not a substitute for installing a security update when one is available.

3. Verify any Apple threat notification directly

If Apple sends a threat notification, sign in to account.apple.com by typing the address yourself and check for the alert at the top of your Apple Account page. Apple says genuine notifications also appear on the iPhone and arrive by email. They will not ask you to provide your password or verification codes, click a link, install a profile, or install an app. Apple’s guidance, published August 13, 2026, says most people will never be targeted by mercenary spyware; its threat notifications are high-confidence alerts for individuals Apple believes have been targeted.

4. If you suspect compromise, protect accounts from a trusted device

Use a different, trusted device to change passwords for your Apple Account and important email accounts, and review account access and recovery details. This can help limit further account access, but it cannot establish whether an iPhone was infected or undo information already copied from it. If the phone is part of an organization, contact its security team before taking steps that could affect an investigation.

5. Seek specialist detection when the risk justifies it

For a technical check, iVerify says its iVerify Basic app can check for infection. Organizations can also assess mobile endpoint detection and response (EDR) products, including offerings from iVerify and Lookout. These are vendor products; confirm current availability, capabilities, and suitability before relying on one. A generic VPN, screen protector, phone case, or unrelated antivirus app is not a documented defense against DarkSword.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to think about your personal risk

Situation What it means Priority
iPhone can install a current patched iOS release Installing the latest supported release addresses the vulnerabilities patched for that device. Update now.
iPhone cannot install a patched release The device may remain exposed to vulnerabilities not fixed in its installed software. Use Lockdown Mode and seek device-specific security advice.
High-risk role or Apple threat notification Risk deserves a more cautious response; an Apple notification is a high-confidence alert, not a generic warning. Verify the notification at account.apple.com, enable Lockdown Mode, and seek specialist help.
No notification and an updated iPhone No notification is not a certificate that a device is clean, but the published campaigns do not establish that ordinary users generally have been infected. Keep iOS current and avoid treating exposure estimates as infection counts.

What the public disclosures do—and do not—establish

The reports establish that exploit chains were used in targeted campaigns and that vulnerable iPhones could face serious data theft without the user knowingly installing spyware. They do not establish that 270 million phones were infected, that every iPhone is vulnerable, or that every recipient of a malicious link was compromised. Apple says mercenary spyware attacks are costly and often have a short shelf life, and that the vast majority of users will never be targeted. That is not a reason to postpone updates: patching is the direct defense available to iPhone owners.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.