DarkSword iOS Exploit Kit Leaked: Hundreds of Millions of iPhones at Risk
A sophisticated full-chain iOS exploit kit dubbed DarkSword was publicly leaked on GitHub in March 2026, exposing hundreds of millions of iPhone users to potential spyware attacks. The exploit targets iOS versions 18.4 through 18.7 using six security flaws, including three previously unknown zero-day vulnerabilities that enable complete device takeover.
According to cybersecurity researchers, DarkSword had been actively deployed by multiple commercial surveillance vendors and state-sponsored threat actors since at least November 2025 before its public leak. The kit was used to steal sensitive personal data from iPhone users across at least four countries.
The public leak significantly lowered the barrier to entry for less sophisticated threat actors, transforming what was previously an advanced surveillance tool into something accessible to common cybercriminals. TechCrunch reported that the exploit kit's publication means anyone with basic technical skills can now target iPhones running outdated iOS versions.
Apple has since patched the vulnerabilities in newer iOS releases, but the risk persists for users who have not updated their devices. The incident highlights the growing market for mobile exploit kits and the cascading risks when surveillance tools leak from their intended users into the broader criminal ecosystem.
For enterprise security teams, DarkSword is a reminder that mobile device management and prompt OS updates remain critical defensive measures. The exploit's ability to achieve full device compromise — from initial contact to data exfiltration — through a single chain makes it particularly dangerous for high-value targets.
The DarkSword leak demonstrates the escalating risk of surveillance technology proliferation — when nation-state exploit kits leak publicly, the threat landscape shifts overnight from targeted espionage to mass criminal exploitation of mobile devices.
Which iOS versions are affected by DarkSword?
DarkSword targets iOS 18.4 through 18.7 using six vulnerabilities including three zero-days. Apple has patched these in newer iOS versions, so updating your device is the primary defense.