Security researchers and media reports say the DarkSword iOS exploitation tool has moved from a targeted threat to a broader operational risk, with evidence that attackers can compromise hundreds of millions of iPhones and that exploit code has leaked publicly. Reporting from WIRED, Lookout, iVerify, and AppleInsider describes DarkSword as a powerful zero-click attack capability seen in the wild, raising concern that well-resourced espionage-style techniques are becoming more accessible to additional threat actors.
Apple responded by issuing and then expanding protections, including rare backported patches for older supported devices to shield users who had not yet moved to newer iOS releases. iVerify said its investigations uncovered signs of zero-click mobile exploitation in the United States and warned that mass iOS attacks now represent a serious enterprise risk, while public reporting stressed that organizations and consumers should update affected iPhones immediately as leaked exploit code increases the likelihood of wider abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
AppleInsider reported that code for the severe iOS hacking technique had leaked broadly, increasing the risk that more attackers could weaponize it. The report framed the situation as leaving users little time to update affected devices.
iVerify published analysis saying the new DarkSword exploit confirms that mass exploitation of iPhones has become a serious enterprise risk, emphasizing broader operational and business impact. This marked a technical and strategic escalation in public understanding of the threat.
iVerify disclosed evidence of zero-click mobile exploitation affecting users in the United States, indicating that advanced mobile attacks were not limited to isolated overseas targeting. The findings added broader victimology and geographic scope to the DarkSword-era threat picture.
Apple said it would ship unusual backported fixes so users on older iOS 18-supported devices would also receive protection from the DarkSword hacking tool. This expanded mitigation beyond the newest OS branch.
Following reports of DarkSword exploitation, Apple issued iOS security updates to fix the underlying vulnerabilities affecting supported devices. The updates were presented as urgent because the exploit chain could be used against large numbers of iPhones.
Lookout reported that attackers were using the DarkSword hacking tool against iPhone users, establishing that the exploit chain was active in real-world attacks. Wired and other later coverage describe the same in-the-wild discovery rather than a separate event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
appleinsider.com
Open sourceiverify.io
Open sourceiverify.io
Open sourcegizmodo.com
Open sourcewired.com
Open sourcewired.com
Open sourcelookout.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.