Cybersecurity & Privacy — 2026-03-23

CISA Orders Federal Agencies to Patch DarkSword iOS Exploit Chain; State Actors Targeting 270M iPhones

CISA added three Apple vulnerabilities exploited through the DarkSword iOS full-chain exploit kit to its Known Exploited Vulnerabilities catalog, mandating federal agency patching by April 3. The DarkSword chain exploits Safari WebKit memory corruption (CVE-2025-31277, CVSS 8.8) and two kernel vulnerabilities to achieve full device compromise. The Cloud Security Alliance assessed DarkSword is being used by multiple state actors. The exploit targets 270 million iPhones via maliciously crafted web content, with previous analysis linking campaigns to Ukrainian website compromise vectors attributed to Russian espionage.

2 sources
  1. CISA orders feds to patch DarkSword iOS flaws exploited attacks - BleepingComputer
  2. CISA Issues Warning on Apple Vulnerabilities Exploited Through DarkSword iOS Chain - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE