Apple has taken the rare step of expanding the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader set of devices on April 1, 2026, pushing critical backported security patches to millions of users still running iOS 18 who remain exposed to DarkSword, a sophisticated, web-delivered exploit chain capable of silently stealing vast amounts of sensitive user data.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout.
The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
Once deployed, DarkSword exfiltrates passwords, messages, browser history, location data, cryptocurrency wallet contents, and even Apple Health data within seconds before wiping its own traces.
In March 2026, the DarkSword toolkit was publicly leaked on GitHub, dramatically lowering the barrier for less sophisticated threat actors to weaponize it. Multiple commercial surveillance vendors and suspected state-sponsored actors had already deployed it against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
iOS 18.7.7 was initially released on March 24, 2026, but Apple extended its availability to a wider device pool on April 1, 2026, specifically citing the DarkSword threat.
This is an unusual policy shift; Apple has historically required users to upgrade to the latest major iOS release to receive security fixes. The company confirmed that the underlying DarkSword patches originally shipped in 2025 but are now being backported to protect the approximately 20% of users still on iOS 18.
The update patches 20+ vulnerabilities spanning critical system components:
The update applies to a broad range of devices, including iPhone XR through iPhone 16e, and a wide range of iPad models from the 5th-generation iPad mini to iPad Pro M4. Users with Automatic Updates enabled will receive iOS 18.7.7 automatically.
Apple has additionally confirmed that its Lockdown Mode feature provides protection against DarkSword for high-risk users who need enhanced hardening.
For comprehensive long-term protection, Apple continues to recommend upgrading to iOS 26.3 or later, where all DarkSword-related vulnerabilities have been fully addressed.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…