Imagine losing every password, message, and photo on your iPhone—not because you clicked a suspicious link, but because you simply visited a website. That nightmare scenario just became a real possibility for hundreds of millions of iPhone users.
A powerful iPhone hacking toolkit called DarkSword has been publicly leaked on GitHub, turning what was once an elite state-sponsored weapon into something any skilled hacker can download and deploy. Security researchers estimate that roughly 270 million iPhones remain vulnerable right now. Here is everything you need to know to protect yourself.
Key Takeaways
- DarkSword is an iPhone exploit kit that was leaked publicly, putting an estimated 270 million devices at risk
- The attack works through Safari—just visiting a compromised website can trigger a full device takeover
- It steals messages, passwords, photos, location data, crypto wallets, and more
- iPhones running iOS 18.4 through 18.7 are vulnerable—updating to iOS 18.7.3 or iOS 26.3+ patches the flaws
- Enabling Lockdown Mode blocks both DarkSword and related exploit kits entirely
What Is DarkSword?
DarkSword is a complete exploit chain and infostealer written in JavaScript. It chains together six different iOS vulnerabilities—including three that were zero-day exploits when first used—to gain full control of an iPhone without the owner ever knowing.
The toolkit has been in active use since late last year, originally deployed by state-sponsored hackers and commercial spyware vendors. But everything changed when the full source code appeared on GitHub, making it accessible to virtually anyone with intermediate coding skills.
Think of it like this: a master key that once only governments possessed is now freely available online. That is why security agencies like CISA have issued emergency directives ordering federal employees to patch their devices immediately.
How the Attack Works
Here is where it gets unsettling. DarkSword does not require you to download anything or approve any permissions. The attack chain works like this:
- You visit a compromised website using Safari. The page contains a hidden malicious iframe.
- The exploit breaks out of Safari's sandbox by exploiting a WebContent vulnerability.
- It leverages WebGPU to inject malicious code into a system process called mediaplaybackd.
- It gains kernel-level access, which means it can read and write to the deepest parts of your operating system.
- It modifies sandbox restrictions to access every app and data store on the device.
The entire process happens silently in the background. No pop-ups. No warnings. No indication that anything happened at all.
What Data Does DarkSword Steal?
The short answer: almost everything. Once DarkSword has kernel-level access, it exfiltrates a staggering amount of personal data. Here is the full list:
- Messages: SMS, iMessage, WhatsApp, and Telegram conversations
- Credentials: Saved passwords from the iOS Keychain, including Wi-Fi passwords
- Browsing data: Safari cookies, browsing history, and saved logins
- Personal data: Contacts, call history, calendar entries, notes, and health data
- Media: Photos and iCloud Drive files
- Location: GPS and location history
- Financial data: It actively targets cryptocurrency wallet apps and major exchange apps
- Device info: SIM information, installed app list, and unique device identifiers
So what does this mean for you? If your iPhone is running a vulnerable iOS version, a single visit to a compromised website could hand over your entire digital life to an attacker.
Who Is at Risk?
DarkSword targets iPhones running iOS 18.4 through iOS 18.7. That might sound like old software, but the numbers tell a different story. An estimated 25% of all active iPhones worldwide still run some version of iOS 18, which translates to roughly 270 million devices.
Why are so many people still on older iOS versions? Several reasons:
- Older hardware: Some iPhones cannot run the latest iOS versions
- Update fatigue: Many users delay or ignore update notifications
- Enterprise devices: Some organizations lock devices to specific iOS versions for compatibility
- Storage constraints: Users with full storage often skip updates
If you are unsure which version you are running, go to Settings > General > About and check your iOS version number right now.
How to Protect Your iPhone
The good news is that protecting yourself is straightforward. Here is exactly what you need to do:
Update Your iOS Immediately
This is the single most important step. iOS 26.3 and newer patches all six vulnerabilities used by DarkSword. If your device cannot run iOS 26, update to at least iOS 18.7.3, which also includes the necessary security fixes. Go to Settings > General > Software Update to check.
Enable Lockdown Mode
Apple's Lockdown Mode was designed specifically for situations like this. When enabled, it blocks both DarkSword and related exploit kits entirely by restricting the attack surfaces they rely on. You can enable it under Settings > Privacy and Security > Lockdown Mode.
Additional Security Steps
- Use a strong device passcode—avoid simple 4-digit PINs
- Enable two-factor authentication on your Apple account
- Avoid installing apps from outside the App Store
- Be cautious with links from unknown sources, especially in messages and emails
- Review your installed apps and remove anything you do not recognize
Why This Leak Is Different
iPhone exploits are discovered regularly, and Apple patches them. But this situation is fundamentally different for one critical reason: the full exploit kit is now public.
Previously, DarkSword was used by a small number of sophisticated attackers—government agencies and spyware companies with the resources to develop or purchase these tools. The GitHub leak changed that equation overnight. Now, any motivated attacker can download the code, study it, and deploy it against unpatched devices.
Google's Threat Analysis Group has already documented multiple threat actors adopting the leaked code. Security researchers expect a surge in attacks targeting the remaining 270 million vulnerable devices before their owners get around to updating.
The clock is ticking. Every day you wait to update is another day your device remains an open target.
Frequently Asked Questions
Is my iPhone affected by the DarkSword exploit?
If your iPhone runs iOS 18.4 through iOS 18.7, it is vulnerable. Check your iOS version under Settings > General > About. Updating to iOS 18.7.3 or iOS 26.3 and newer patches all the vulnerabilities.
Can DarkSword hack my iPhone without me clicking anything?
Yes. DarkSword uses a drive-by download attack. Simply visiting a compromised website in Safari is enough to trigger the exploit chain. No clicks, downloads, or permissions are required from the user.
Does Lockdown Mode protect against DarkSword?
Yes. Apple's Lockdown Mode blocks the attack vectors used by both DarkSword and the related Coruna exploit kit. It is an effective defense even on devices running vulnerable iOS versions.
What should I do if I think my iPhone was compromised?
Update your iOS immediately. Change all passwords stored on your device, especially for email, banking, and social media. Enable two-factor authentication everywhere. Consider using a mobile security tool like iVerify to scan for indicators of compromise.
Why did Apple not prevent this leak?
The exploit kit was developed by third parties, not Apple. Apple patched the underlying vulnerabilities before the public leak. The issue is that millions of users have not yet applied the available updates, leaving their devices exposed.
The Bottom Line
DarkSword is a stark reminder that your iPhone is only as secure as its latest update. The exploit kit is now freely available online, multiple threat actors have already adopted it, and 270 million devices remain vulnerable.
The fix takes less than five minutes. Open Settings, tap Software Update, and install the latest version. If your phone supports Lockdown Mode, turn it on. These two steps eliminate the DarkSword threat entirely.
Do not wait until the next headline is about a massive data breach traced back to this exploit. Update your iPhone right now.

