Cybersecurity & Privacy — 2026-03-25
DarkSword iOS Exploit Kit Leaked on GitHub, Putting Hundreds of Millions of iPhones at Risk
A sophisticated iOS spyware and exploit kit called DarkSword, previously attributed to suspected Russian state-backed hackers, was publicly posted on GitHub. The toolkit contains multiple zero-day exploits targeting iOS 18, which runs on approximately 25% of active iPhones. Security researchers warn the leak "democratizes" iPhone hacking capabilities that were previously restricted to nation-states due to development costs. CISA issued an advisory warning of Apple flaws exploited via the DarkSword attack chain. Apple has released patches in iOS/macOS 26.4.
Analysis
The timeline matters: Apple shipped patches in iOS/macOS 26.4 on March 25, meaning the vulnerability window between leak and patch is narrow for users who update promptly. However, with 25% of iPhones still on iOS 18, the vulnerable population is substantial. The Russian attribution of the original toolkit, combined with the leak timing during the Iran war, raises questions about whether the release was intentional to increase the attack surface against Western targets.
The timeline matters: Apple shipped patches in iOS/macOS 26.4 on March 25, meaning the vulnerability window between leak and patch is narrow for users who update promptly. However, with 25% of iPhones still on iOS 18, the vulnerable population is substantial. The Russian attribution of the original toolkit, combined with the leak timing during the Iran war, raises questions about whether the release was intentional to increase the attack surface against Western targets.
1 sources
- iOS, macOS 26.4 Roll Out With Fresh Security Patches -
SecurityWeek