Why You Should Update Your iPhone Now to Avoid the New ‘DarkSword’ Exploit
Google’s Threat Intelligence Group has uncovered a sophisticated new hacking tool named DarkSword that has been used to secretly compromise iPhones in several countries.
Security experts found that multiple groups, including commercial surveillance companies and state-sponsored hackers, have been using this single exploit chain to spy on users in Ukraine, Saudi Arabia, Turkey, and Malaysia.
The DarkSword attack is dangerous because it uses a series of several technical vulnerabilities to bypass Apple’s security. It specifically targets iPhones running older versions of the current software. Once a device is infected, hackers can install various types of spyware to steal private messages, location history, photos, and even record audio from the microphone.
How the Attack Works
Hackers typically lure victims to a compromised or fake website. For example, one campaign used a fake Snapchat-themed page to target users. Once a person visits the site on their iPhone, the DarkSword code runs automatically in the background.
The attack happens in a specific sequence that begins when a malicious website checks if you are using an iPhone and which version of the software you have. Next, it uses a flaw in Safari to run unauthorized code. The hack then jumps through different layers of the iPhone’s software to gain full control over the device. Finally, the spyware is installed to begin harvesting your personal data and sending it back to the attackers.
Is Your Phone Safe?
The good news is that Google reported these flaws to Apple, and they have already been fixed. Most of the vulnerabilities were patched recently, and the final remaining holes were closed with updates, specifically iOS 26.3 (released back in February). So yes, you should be installing updates when Apple releases them (and ensure automatic updates are enabled).
Google recommends enabling Apple’s Lockdown Mode for extreme protection, and to always install the latest software updates for your phone. Also you should never click links randomly sent to you by text or email.
Want to see more of our stories on Google?
P.S. Want to keep this site truly independent? Support us by buying us a beer, treating us to a coffee, or shopping through Amazon here. Links in this post are affiliate links, so we earn a tiny commission at no charge to you. Thanks for supporting independent Canadian media!
