The warning from SlowMist Chief Information Security Officer 23pds suggests that the exploit, previously documented by Google as affecting versions 18.4 through 18.7, has been modified to compromise newer software releases. Darksword functions as a full exploit chain, combining six distinct vulnerabilities to gain root-level access to an iPhone. Once inside, attackers can dismantle the sandbox isolation that typically prevents apps from accessing data stored by others, putting sensitive wallet credentials at risk.
Unlike traditional malware requiring installation, Darksword initiates through social engineering. Victims are lured to malicious web pages via messaging apps or social media, where Safari processes the exploit automatically. Google’s research previously linked the tool to state-aligned groups and commercial surveillance providers targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. While Apple patched the original vulnerabilities in subsequent updates, the current claims regarding iOS 26.5 remain unconfirmed by either Apple or Google. Security experts maintain that keeping devices updated is the primary defense, as attackers continue to pivot toward browser-based vectors to circumvent app store oversight.

Comments (0)
No comments yet. Be the first!