Hundreds of millions of iPhones at risk: Google reveals critical darksword vulnerability

March 19, 2026  16:03

Researchers from Google, in collaboration with iVerify and Lookout, have discovered one of the most dangerous vulnerabilities in the history of iOS. A chain of six interconnected flaws, collectively named DarkSword, allows attackers to gain full control of a device through a regular website. The threat affects hundreds of millions of iPhones running iOS 18.4–18.7, according to Wired.

How the attack works

Everything begins with clicking a malicious link — the site may be disguised as a popular resource: a bank, social network, online store, or even a news portal. As soon as the page loads, a chain of exploits is silently launched on the device.

The key point is that the vulnerability allows execution of arbitrary code with kernel privileges. This gives the attacker full access to all content on the iPhone:

passwords and autofill data;
photos, videos, documents;
messages in iMessage, WhatsApp, Telegram, and other messengers;
browser history;
data from banking apps and crypto wallets.

The attacker can read, write, and delete files, turn on the camera and microphone, track geolocation — effectively turning the phone into a surveillance device.

Who is affected and how Apple responded

The vulnerability affects iOS 18.4–18.7 — millions of devices worldwide, including those that have not yet been updated to the latest versions.

Apple fixed the issue in updates iOS 18.7.2, iOS 18.7.3, and in the next major version (iOS 26 under internal numbering). However, many users are still running vulnerable builds — either due to delaying updates or because of corporate policies that postpone them.

Experts emphasize that there is currently no confirmed evidence that the vulnerability has been actively exploited in the wild, but its complexity and scale make it highly attractive for state-sponsored hackers and cybercriminal groups.

What users should do right now

Immediately update your iPhone to the latest version of iOS (Settings → General → Software Update).
Do not click on suspicious links, even if they come from people you know.
Enable two-factor authentication wherever possible.
Check for suspicious configuration profiles (Settings → General → VPN & Device Management).

In brief

Google, iVerify, and Lookout discovered a critical vulnerability called DarkSword — a chain of six flaws in iOS 18.4–18.7 that allows full control of an iPhone (kernel-level access) through a malicious website. It affects hundreds of millions of devices. Attackers can access passwords, photos, messages, and crypto wallets. Apple fixed the issue in iOS 18.7.2, 18.7.3, and iOS 26. Update immediately.


 
 
 
 
  • Archive