[HN Gopher] Hundreds of Millions of iPhones Can Be Hacked With a...
       ___________________________________________________________________
        
       Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found
       in the Wild
        
       Author : WalterSobchak
       Score  : 106 points
       Date   : 2026-03-18 14:28 UTC (8 hours ago)
        
 (HTM) web link (www.wired.com)
 (TXT) w3m dump (www.wired.com)
        
       | joezydeco wrote:
       | I got an alert this morning for an iOS update numbered 26.3.1(a).
       | 
       | (a)? This must be _really bad_.
        
         | FuriouslyAdrift wrote:
         | Impact: Processing maliciously crafted web content may bypass
         | Same Origin Policy
         | 
         | Description: A cross-origin issue in the Navigation API was
         | addressed with improved input validation.
         | 
         | WebKit Bugzilla: 306050
         | 
         | CVE-2026-20643: Thomas Espach
        
         | dewey wrote:
         | > It can take over devices running iOS 18 that simply visit
         | infected websites.
         | 
         | I wonder if this is supposed to be > iOS 18 or really just
         | version 18?
        
           | quentindanjou wrote:
           | It's in the source article (from Google Research group):
           | 
           | > DarkSword supports iOS versions 18.4 through 18.7
           | 
           | https://cloud.google.com/blog/topics/threat-
           | intelligence/dar...
           | 
           | The source exploits continued to be patched with all of them
           | patched in iOS 26.3
        
             | dewey wrote:
             | Oh, I was confused why the article was so short and chalked
             | it up to it being some developing story. Turns out there's
             | a "You've read your last free article." heading that hides
             | the rest but it's not very obvious that there's an article
             | hiding.
        
         | bombcar wrote:
         | What device? I don't see anything beyond 26.3.1 on my iPhone 15
         | PromaxXDR(tm)
        
           | joezydeco wrote:
           | iPhone 15 (vanilla) running iOS 18.7.2. I now have a
           | permanent notification on my lock screen nagging me to update
           | to iOS 26.
        
             | qaz_plm wrote:
             | Enabling beta updates for ios18 should kill the nagging
             | notification.
        
               | joezydeco wrote:
               | I'm keeping it there to remind me to stay defiant against
               | the shittier UI. I'll wait until they can put it on a
               | user switch or create a more readable option for older
               | users. Which will probably be 'never'.
        
               | a012 wrote:
               | I'm on the same boat. I was forced to update to the
               | shitty UI at work, but not on my personal phone.
        
               | joezydeco wrote:
               | Same here. Which helped me confirm how bad it was.
        
               | 6510 wrote:
               | redmagic 11 is almost 1000 usd cheaper than the s25.
        
               | fn-mote wrote:
               | But still only gets you to 18.7.3
        
           | aurea wrote:
           | The update can be found under
           | 
           | Settings > Privacy & Security > Background Security
           | Improvements
        
             | bombcar wrote:
             | There it is, and I've never seen that area before.
        
         | eugenekolo wrote:
         | Unrelated bug as far as I can tell.
        
       | jryio wrote:
       | Here is the Google Research group's writeup
       | 
       | https://cloud.google.com/blog/topics/threat-intelligence/dar...
       | 
       | Relevant forward:
       | 
       | > GTIG has identified several different users of the DarkSword
       | exploit chain dating back to November 2025. In addition to the
       | case studies on DarkSword usage documented in this blog post, we
       | assess it is likely that other commercial surveillance vendors or
       | threat actors may also be using DarkSword.
       | 
       | > Google Threat Intelligence Group (GTIG) has identified a new
       | iOS full-chain exploit that leveraged multiple zero-day
       | vulnerabilities to fully compromise devices. Based on toolmarks
       | in recovered payloads, we believe the exploit chain to be called
       | DarkSword. Since at least November 2025, GTIG has observed
       | multiple commercial surveillance vendors and suspected state-
       | sponsored actors utilizing DarkSword in distinct campaigns. These
       | threat actors have deployed the exploit chain against targets in
       | Saudi Arabia, Turkey, Malaysia, and Ukraine.
       | 
       | > DarkSword supports iOS versions 18.4 through 18.7 and utilizes
       | six different vulnerabilities to deploy final-stage payloads.
       | GTIG has identified three distinct malware families deployed
       | following a successful DarkSword compromise: GHOSTBLADE,
       | GHOSTKNIFE, and GHOSTSABER. The proliferation of this single
       | exploit chain across disparate threat actors mirrors the
       | previously discovered Coruna iOS exploit kit. Notably, UNC6353, a
       | suspected Russian espionage group previously observed using
       | Coruna, has recently incorporated DarkSword into their watering
       | hole campaigns.
        
         | alecco wrote:
         | This should be the post, not Wired's blogspam.
        
         | bix6 wrote:
         | I know everyone hates liquid glass but isn't that better
         | security wise than being on an iOS that's 8 versions behind?
        
           | jryio wrote:
           | There are not 8 major versions between iOS 18 and iOS 26.
           | Apple skipped the monotonously increasing version numbering
           | system since iOS 1 during WDDC 2025 to adopt a year suffix
           | based versioning system.
           | 
           | iOS 17, then iOS 18, then iOS 26, then iOS 27.
           | 
           | You're not the only party confused.
        
             | bix6 wrote:
             | Haha thanks! Good to know they are on years now. Back to
             | random version numbers in 5 year? :p
        
               | reactordev wrote:
               | Semver has always been king
        
               | sunnybeetroot wrote:
               | How is increasing by 1 every year random? :P
        
             | skygazer wrote:
             | Edit: Oop, I misread! Right, yes, the change up was
             | arguably not entirely boring. Some people were excited at
             | least.
             | 
             | Originally: To be the annoying pedant, version numbers did
             | still monotonically increase, even with the gap, because
             | each version is >= to the last. The mono means a single
             | direction, not a step size of one.
        
               | ticulatedspline wrote:
               | to be an even more annoying pedant. they technically said
               | "monotonously" not monotonically, though skipping to 26
               | still seems pretty monotonous.
        
         | echelon_musk wrote:
         | I wonder if that means 18.7.4 is vulnerable for all the Liquid
         | Glass haters?
        
           | lynndotpy wrote:
           | It's vulnerable, but iOS 18 since iOS 18.7.3 is only
           | available for the 2018 iPhone XS and XR.
        
       | BTAQA wrote:
       | The interesting angle here is what this means for passes and
       | credentials stored in Apple Wallet. If device compromise is this
       | accessible, the assumption that Wallet passes are isolated from
       | the rest of the device needs more scrutiny. Apple's security
       | model relies heavily on the secure enclave but a tool like this
       | changes the threat surface significantly.
        
         | ozlikethewizard wrote:
         | This is always the threat with walled garden style security.
         | When you couple applications so tightly in an intrinsic trust
         | network, on the basis that no external attacker can gain
         | access, then the internal security is neglected and it only
         | takes the weakest link.
        
       | ramesh31 wrote:
       | Welp, I've been holding on out that liquid glass crap as long
       | possible. Guess my phone is just going to suck now.
        
         | bombcar wrote:
         | If it's really as bad as all that, they'll patch existing older
         | releases.
        
           | pfortuny wrote:
           | One can hope but I do not trust them.
        
           | xoa wrote:
           | > _If it 's really as bad as all that, they'll patch existing
           | older releases._
           | 
           | They have patched existing releases of iOS 18... but then
           | they artificially restricted those patches only to a couple
           | of phone models that don't support iOS 26. So if you're on a
           | vaguely modern iDevice and are still on 18 because you don't
           | want the new UI and other fuckups you are not allowed to
           | install the patched 18. It'd be one thing if you had a phone
           | that simply never supported iOS 18 at all, or if Apple wasn't
           | patching iOS 18 at all for anyone, but that they've gone to
           | the effort to fix it but then also used it as another lever
           | for force upgrades is really sucky.
        
             | JumpCrisscross wrote:
             | > _you are not allowed to install the patched 18_
             | 
             | Is it "you are not allowed," or Cupertino isn't going to
             | bother developing and testing?
        
               | xoa wrote:
               | > _Is it "you are not allowed," or Cupertino isn't going
               | to bother developing and testing?_
               | 
               | It is very firmly "you are not allowed". In fact you're
               | not even allowed to switch back to iOS 18 at all. Only
               | actively signed iOS IPSWs can be installed (barring
               | historical cases where someone had saved signing
               | tickets). You can see the current status at sites like
               | https://ipsw.me and if you're on any iOS 26 supported
               | iDevice currently only 26.3.1 is signed. The last iOS 18
               | version was 18.6.2 from August of last year. If you go
               | back to the iPhone XS/XR, you'll see they're still
               | updating iOS 18, with 18.7.6 released two weeks ago
               | (March 4), but they've chosen to force anyone who wants
               | security updates to move to iOS 26 instead.
        
               | JumpCrisscross wrote:
               | The rollback provisions, granted. But I'm arguing the
               | other stuff requires QC attention Apple may not want to
               | provide to a legacy line. That isn't not allowing
               | something that can be done. It's not building something
               | they don't want to.
        
             | zzrrt wrote:
             | To be fair, it would cost them more to fully test the iOS
             | 18 patches on all devices, than what it cost them to test a
             | few devices. So I wouldn't quite call it artificially
             | holding the patches back. But yeah, it is probably mostly
             | motivated by avoiding bad PR of letting slightly-older
             | devices get hacked, and then forcing everyone else to be on
             | the new release. (FWIW I'm running iOS 18 on an iPhone SE
             | 2020, so probably going to have to embrace all the change
             | and bugs in iOS 26.)
        
           | lynndotpy wrote:
           | No. Apple already released the patch in February, and Apple
           | chose not not patch older releases.
           | 
           | Apple of 2026 is not the same Apple of 2025. The people at
           | Apple have held back iOS 18.7.3, iOS 18.7.4, iOS 18.7.5, or
           | iOS 18.7.6 for most iPhones that support iOS 18.
           | 
           | These are dozens of CVEs patched in these updates, including
           | numerous exploits as bad or worse than the one described in
           | this one. (Article is paywalled so I couldn't read it, so I
           | am getting the details from Google's post
           | https://cloud.google.com/blog/topics/threat-
           | intelligence/dar...
           | 
           | - CVE-2025-43541, CVE-2025-43501 WebKit zero day https://www.
           | theregister.com/2025/12/15/apple_follows_google_... (iOS
           | 18.7.3)
           | 
           | - CVE-2025-43529 and CVE-2025-14174, mentioned in the article
           | (iOS 18.7.3)
           | 
           | - The dyld exploit fixed in iOS 18.7.5, and the exploit in
           | this article
           | https://www.theregister.com/2026/02/12/apple_ios_263/ (iOS
           | 18.7.5)
           | 
           | Unfortunately, in iOS 26, there is a new bug where Lockdown
           | Mode breaks call recording, which is something I rely on.
           | Something to weigh for anyone on iOS 18 who is considering
           | installing iOS 26.
        
             | walterbell wrote:
             | _> Lockdown Mode breaks call recording_
             | 
             | Do you mean screen recording? What are the symptoms of the
             | bug?
        
               | lynndotpy wrote:
               | Nope, call recording. Not sure how universal this is, but
               | phone call recording immediately stops with the "This
               | call is no longer being recorded" effect afterwards.
        
         | msk-lywenn wrote:
         | Apple is probably going to issue an update for 18. Heck they
         | released a security update for coruna on 15.x last week. Same
         | thing maybe?
        
           | lynndotpy wrote:
           | No, they are not. Apple is choosing to only release the iOS
           | 18 security patches for the XS and XR.
        
         | dhosek wrote:
         | Liquid glass isn't too bad on the iPhone or even the iPad. It's
         | mostly on the Mac that it sucks.
        
         | neom wrote:
         | I thought the same thing but updated couple weeks back and
         | actually really really enjoy the liquid glass. I don't recall
         | what it was about the release that made me think I'd hate it,
         | but I've half fallen in love with it, I was just thinking
         | yesterday I wonder what all the fuss was about.
        
           | Analemma_ wrote:
           | I don't like it on the iPhone, but it's more a "sigh, I'll
           | live with it" downgrade than a catastrophic one (at least
           | once you go into the Safari settings and turn off the huge
           | useless address bar by putting it in compact mode). It's on
           | the Mac where it's truly a shitshow.
        
           | thejazzman wrote:
           | I believe it's changed a lot since it was initially debut'd
           | via the betas. And there was that Supabase post mocking it,
           | where they made the whole UI glass, and that biased me a bit
           | ha
        
       | k2enemy wrote:
       | I'm really hoping Apple backtracks on its refusal to update the
       | 18.x line for phones that are compatible with 26. At least
       | provide a security update.
        
         | kace91 wrote:
         | Their design disaster must be hidden in metrics, damn be
         | security.
        
         | lynndotpy wrote:
         | Apple used to have a really good security record, it's mind
         | boggling they blew it all up just to force Liquid Glass on
         | users.
         | 
         | For those not in the loop, Apple used to provide security
         | patches for supported older iOS versions. They changed a lot of
         | behavior around the release of Liquid Glass (iOS 26, MacOS
         | Tahoe). Starting with iOS 18.7.3, they only release patch
         | versions for the iPhone XS and XR. They've repeated this,
         | through to 18.7.6 now.
         | 
         | So much goodwill and trust, obliterated.
        
           | walterbell wrote:
           | _> Starting with iOS 18.7.3, they only release patch versions
           | for the iPhone XS and XR. They 've repeated this, through to
           | 18.7.6 now._                 iPhone XS/XR: the only Usable +
           | Secure iPhone in 2026
        
           | yborg wrote:
           | It's especially glaring since Apple just released a fix for a
           | Coruna exploit that patched iOS 15.
        
           | titzer wrote:
           | Those trillions of dollars aren't going to find their way
           | into the pockets of the shareholders if they have to pay some
           | rubes to maintain old stuff!
        
             | 6510 wrote:
             | I'm always surprised what isn't a national security issue.
        
             | walterbell wrote:
             | _> to pay some rubes to maintain old stuff_
             | 
             | Can LLMs backport fixes to stable branches?
        
               | lynndotpy wrote:
               | Well, Apple already fixed the code, Apple is just
               | choosing not to release it for most iPhones.
        
           | floralhangnail wrote:
           | That's interesting, as they released security patches for iOS
           | 15 devices like iPhone 6 as recent as a week ago.
        
           | fortran77 wrote:
           | Apple was always defeated in every pwn2own competition. I'm
           | not sure if their security is any better or worse than anyone
           | else.
        
         | pfortuny wrote:
         | Not going to happen (despite my still being on 18.x) because
         | they want to force you to upgrade to 26 for publicity. As
         | simple as that.
         | 
         | The new "security upgrade available" will (I bet) be "to 26".
        
           | JumpCrisscross wrote:
           | > _for publicity_
           | 
           | Or don't want to maintain two different security
           | architectures.
        
             | pfortuny wrote:
             | They security-updated iOS 15 a couple of months ago, so
             | that does not seem likely.
        
           | JumpCrisscross wrote:
           | > _for publicity_
           | 
           | Or don't want to maintain two different security
           | architectures. Apple has always been visually opinionated.
        
             | pfortuny wrote:
             | They security-updated iOS 15 a couple of months ago, so
             | that does not seem likely.
        
         | varispeed wrote:
         | Apple should stop doing security by obscurity in the first
         | place. People have no way finding out whether their phones have
         | been compromised. Lockdown mode is just a cope mechanism for
         | phones likely already compromised and there is no guarantee
         | lockdown mode cannot be bypassed.
         | 
         | Apple hardware is inherently insecure and it is bizarre that
         | Apple keeps burying their head in the sand.
        
           | unsupp0rted wrote:
           | Aren't their devices the most secure on the mass market?
           | 
           | More than non-obscure phones, laptops, desktops... washing
           | machines, robot vacuums, doorbells, you name it
        
             | varispeed wrote:
             | Yes, but you can use anti-virus software on other platforms
             | which can detect many threats.
             | 
             | Also just because others are not great, doesn't excuse
             | Apple from being very much negligent.
             | 
             | I know many people who bought Apple products specifically
             | because of the myth that they are secure. They were in fact
             | mis sold. There is common thinking that no anti virus
             | software = no viruses = secure among non technical crowd.
        
             | walterbell wrote:
             | _> the most secure_
             | 
             | Except for withholding iOS 18 security fixes when public
             | exploits are fixed in iOS 26.
        
               | unsupp0rted wrote:
               | Even then. I'll take a leaky iOS 18 over pretty much any
               | leaky Android or internet-connected TV or whatever.
               | 
               | iPhones are still the least bad option, for regular
               | people who aren't planning to solder anything, select
               | their boot loader on launch, or recompile a kernel.
        
               | buggeryorkshire wrote:
               | My Pixel 8 Pro is more secure than your iOS 18 handset
               | Apple don't care about.
        
       | hnburnsy wrote:
       | >We also identified additional code added when the actor attempts
       | to infect a user using Chrome, where the x-safari-https protocol
       | handler is used to open the page in Safari (Figure 4). This
       | suggests that UNC6748 didn't have an exploit chain for Chrome at
       | the time of this activity.
       | 
       | Thanks Apple for allowing the overriding of the user's default
       | browser.
        
       | MrDOS wrote:
       | I wish I had a better sense of how these zero-click
       | vulnerabilities work so I could get a sense of how to protect
       | myself from them (you know, _without_ giving in to Liquid Glass).
       | Can they be blocked by an ad blocker? _Are_ they blocked by any
       | extant ad blockers? What about "Lockdown Mode"?
        
         | bix6 wrote:
         | My understand is ad blockers only stop one class. Lockdown Mode
         | is supposedly a major upgrade given all the underlying
         | processes it blocks / slows.
        
         | fn-mote wrote:
         | Note that this is 1-click.
         | 
         | 0-click example: receive an MMS with a malformed image that
         | exploits a bug in decoding
        
           | rsync wrote:
           | "0-click example: receive an MMS with a malformed image that
           | exploits a bug in decoding ..."
           | 
           | Consider a SMS firewall that:
           | 
           | - flattens text to ascii-256
           | 
           | - recompresses, noises and slightly resizes images and video
           | 
           | ... and only then passes the message onto your real (SIM
           | card) phone number.
           | 
           | This, of course, requires that you host your phone number
           | somewhere like Twilio which has other added benefits like
           | additional protection from SIM-jacking and being invulnerable
           | to theft or loss of your handset, etc.
           | 
           | Recommended.
        
         | SimianSci wrote:
         | It's a watering hole attack. At any point your iphone sends an
         | http request to a compromised site, by add, link, embedded,
         | etc. your device will be exploited. there really isn't a way to
         | permanently defeat this. We are about to see an explosion of
         | novel attack types utilizing this exploit as their basis, you
         | realistically cannot defend yourself against these without
         | either updating or no longer using an iphone.
        
           | MrDOS wrote:
           | What are you talking about?
           | 
           | Why are we about to see an explosion?
        
           | walterbell wrote:
           | _> At any point your iphone sends an http request to a
           | compromised site, by add, link, embedded, etc. your device
           | will be exploited._
           | 
           | Would it help to disable Javascript on untrusted sites via
           | Brave?
        
       | throwaway2016a wrote:
       | I was literally just attending a course on "innovation" and the
       | topic of Apple vs Android was covered. Interestingly enough, a
       | majority of students commenting cited iOS "security" as a core
       | value proposition. As an Android user, however, I know there are
       | a lot of CVEs in volume but in terms of severity, when an iOS
       | issue happens it appears to generally be much more severe.
        
       | eugenekolo wrote:
       | It's actually a fascinating find by Lookout, iVerify, and Google.
       | This is a multi million dollar exploit chain sold to various
       | buyers.
       | 
       | Complete full chain 1-click exploit from Safari to complete
       | device take over exfiltrating personal data, passwords, and
       | crypto wallets.
       | 
       | https://www.lookout.com/threat-intelligence/article/darkswor...
       | 
       | https://iverify.io/blog/darksword-ios-exploit-kit-explained
       | 
       | https://cloud.google.com/blog/topics/threat-intelligence/dar...
        
       | walterbell wrote:
       | Is the full exploit chain functional on iPhone 17 MIE/EMTE
       | silicon with Lockdown Mode enabled?
        
         | eugenekolo wrote:
         | No, because Lockdown Mode disabled JIT which is a part of this
         | exploit chain.
        
       | kevincloudsec wrote:
       | the supply chain for offensive tooling is now indistinguishable
       | from the supply chain for malware. take care of your security
       | team!
        
       | geuis wrote:
       | I'd like a security patch for 18. I have no desire to upgrade to
       | iOS Vista or whatever it is we're calling it
        
       | SayThatSh wrote:
       | All these exploits and we still can't get proper jailbreaks on
       | new iOS versions :( I moved away from Android years ago in the
       | interest of digital privacy so it's just wonderful to hear
       | security isn't as tight as I'd hoped haha.. Then again I guess
       | those like myself staying on the bleeding edge version-wise
       | aren't affected.
        
         | eugenekolo wrote:
         | I suspect you'll see one with this or Coruna soon enough.
        
       | DavideNL wrote:
       | https://support.apple.com/en-us/126604
       | 
       |  _iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), macOS
       | 26.3.2 (a)_
       | 
       |  _Released March 17, 2026_
       | 
       |  _WebKit_
       | 
       |  _Available for: iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, macOS
       | 26.3.2_
       | 
       |  _Impact: Processing maliciously crafted web content may bypass
       | Same Origin Policy_
       | 
       |  _Description: A cross-origin issue in the Navigation API was
       | addressed with improved input validation._
       | 
       |  _WebKit Bugzilla: 306050_
       | 
       |  _CVE-2026-20643: Thomas Espach_
        
       ___________________________________________________________________
       (page generated 2026-03-18 23:01 UTC)