[HN Gopher] Hundreds of Millions of iPhones Can Be Hacked With a...
___________________________________________________________________
Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found
in the Wild
Author : WalterSobchak
Score : 106 points
Date : 2026-03-18 14:28 UTC (8 hours ago)
(HTM) web link (www.wired.com)
(TXT) w3m dump (www.wired.com)
| joezydeco wrote:
| I got an alert this morning for an iOS update numbered 26.3.1(a).
|
| (a)? This must be _really bad_.
| FuriouslyAdrift wrote:
| Impact: Processing maliciously crafted web content may bypass
| Same Origin Policy
|
| Description: A cross-origin issue in the Navigation API was
| addressed with improved input validation.
|
| WebKit Bugzilla: 306050
|
| CVE-2026-20643: Thomas Espach
| dewey wrote:
| > It can take over devices running iOS 18 that simply visit
| infected websites.
|
| I wonder if this is supposed to be > iOS 18 or really just
| version 18?
| quentindanjou wrote:
| It's in the source article (from Google Research group):
|
| > DarkSword supports iOS versions 18.4 through 18.7
|
| https://cloud.google.com/blog/topics/threat-
| intelligence/dar...
|
| The source exploits continued to be patched with all of them
| patched in iOS 26.3
| dewey wrote:
| Oh, I was confused why the article was so short and chalked
| it up to it being some developing story. Turns out there's
| a "You've read your last free article." heading that hides
| the rest but it's not very obvious that there's an article
| hiding.
| bombcar wrote:
| What device? I don't see anything beyond 26.3.1 on my iPhone 15
| PromaxXDR(tm)
| joezydeco wrote:
| iPhone 15 (vanilla) running iOS 18.7.2. I now have a
| permanent notification on my lock screen nagging me to update
| to iOS 26.
| qaz_plm wrote:
| Enabling beta updates for ios18 should kill the nagging
| notification.
| joezydeco wrote:
| I'm keeping it there to remind me to stay defiant against
| the shittier UI. I'll wait until they can put it on a
| user switch or create a more readable option for older
| users. Which will probably be 'never'.
| a012 wrote:
| I'm on the same boat. I was forced to update to the
| shitty UI at work, but not on my personal phone.
| joezydeco wrote:
| Same here. Which helped me confirm how bad it was.
| 6510 wrote:
| redmagic 11 is almost 1000 usd cheaper than the s25.
| fn-mote wrote:
| But still only gets you to 18.7.3
| aurea wrote:
| The update can be found under
|
| Settings > Privacy & Security > Background Security
| Improvements
| bombcar wrote:
| There it is, and I've never seen that area before.
| eugenekolo wrote:
| Unrelated bug as far as I can tell.
| jryio wrote:
| Here is the Google Research group's writeup
|
| https://cloud.google.com/blog/topics/threat-intelligence/dar...
|
| Relevant forward:
|
| > GTIG has identified several different users of the DarkSword
| exploit chain dating back to November 2025. In addition to the
| case studies on DarkSword usage documented in this blog post, we
| assess it is likely that other commercial surveillance vendors or
| threat actors may also be using DarkSword.
|
| > Google Threat Intelligence Group (GTIG) has identified a new
| iOS full-chain exploit that leveraged multiple zero-day
| vulnerabilities to fully compromise devices. Based on toolmarks
| in recovered payloads, we believe the exploit chain to be called
| DarkSword. Since at least November 2025, GTIG has observed
| multiple commercial surveillance vendors and suspected state-
| sponsored actors utilizing DarkSword in distinct campaigns. These
| threat actors have deployed the exploit chain against targets in
| Saudi Arabia, Turkey, Malaysia, and Ukraine.
|
| > DarkSword supports iOS versions 18.4 through 18.7 and utilizes
| six different vulnerabilities to deploy final-stage payloads.
| GTIG has identified three distinct malware families deployed
| following a successful DarkSword compromise: GHOSTBLADE,
| GHOSTKNIFE, and GHOSTSABER. The proliferation of this single
| exploit chain across disparate threat actors mirrors the
| previously discovered Coruna iOS exploit kit. Notably, UNC6353, a
| suspected Russian espionage group previously observed using
| Coruna, has recently incorporated DarkSword into their watering
| hole campaigns.
| alecco wrote:
| This should be the post, not Wired's blogspam.
| bix6 wrote:
| I know everyone hates liquid glass but isn't that better
| security wise than being on an iOS that's 8 versions behind?
| jryio wrote:
| There are not 8 major versions between iOS 18 and iOS 26.
| Apple skipped the monotonously increasing version numbering
| system since iOS 1 during WDDC 2025 to adopt a year suffix
| based versioning system.
|
| iOS 17, then iOS 18, then iOS 26, then iOS 27.
|
| You're not the only party confused.
| bix6 wrote:
| Haha thanks! Good to know they are on years now. Back to
| random version numbers in 5 year? :p
| reactordev wrote:
| Semver has always been king
| sunnybeetroot wrote:
| How is increasing by 1 every year random? :P
| skygazer wrote:
| Edit: Oop, I misread! Right, yes, the change up was
| arguably not entirely boring. Some people were excited at
| least.
|
| Originally: To be the annoying pedant, version numbers did
| still monotonically increase, even with the gap, because
| each version is >= to the last. The mono means a single
| direction, not a step size of one.
| ticulatedspline wrote:
| to be an even more annoying pedant. they technically said
| "monotonously" not monotonically, though skipping to 26
| still seems pretty monotonous.
| echelon_musk wrote:
| I wonder if that means 18.7.4 is vulnerable for all the Liquid
| Glass haters?
| lynndotpy wrote:
| It's vulnerable, but iOS 18 since iOS 18.7.3 is only
| available for the 2018 iPhone XS and XR.
| BTAQA wrote:
| The interesting angle here is what this means for passes and
| credentials stored in Apple Wallet. If device compromise is this
| accessible, the assumption that Wallet passes are isolated from
| the rest of the device needs more scrutiny. Apple's security
| model relies heavily on the secure enclave but a tool like this
| changes the threat surface significantly.
| ozlikethewizard wrote:
| This is always the threat with walled garden style security.
| When you couple applications so tightly in an intrinsic trust
| network, on the basis that no external attacker can gain
| access, then the internal security is neglected and it only
| takes the weakest link.
| ramesh31 wrote:
| Welp, I've been holding on out that liquid glass crap as long
| possible. Guess my phone is just going to suck now.
| bombcar wrote:
| If it's really as bad as all that, they'll patch existing older
| releases.
| pfortuny wrote:
| One can hope but I do not trust them.
| xoa wrote:
| > _If it 's really as bad as all that, they'll patch existing
| older releases._
|
| They have patched existing releases of iOS 18... but then
| they artificially restricted those patches only to a couple
| of phone models that don't support iOS 26. So if you're on a
| vaguely modern iDevice and are still on 18 because you don't
| want the new UI and other fuckups you are not allowed to
| install the patched 18. It'd be one thing if you had a phone
| that simply never supported iOS 18 at all, or if Apple wasn't
| patching iOS 18 at all for anyone, but that they've gone to
| the effort to fix it but then also used it as another lever
| for force upgrades is really sucky.
| JumpCrisscross wrote:
| > _you are not allowed to install the patched 18_
|
| Is it "you are not allowed," or Cupertino isn't going to
| bother developing and testing?
| xoa wrote:
| > _Is it "you are not allowed," or Cupertino isn't going
| to bother developing and testing?_
|
| It is very firmly "you are not allowed". In fact you're
| not even allowed to switch back to iOS 18 at all. Only
| actively signed iOS IPSWs can be installed (barring
| historical cases where someone had saved signing
| tickets). You can see the current status at sites like
| https://ipsw.me and if you're on any iOS 26 supported
| iDevice currently only 26.3.1 is signed. The last iOS 18
| version was 18.6.2 from August of last year. If you go
| back to the iPhone XS/XR, you'll see they're still
| updating iOS 18, with 18.7.6 released two weeks ago
| (March 4), but they've chosen to force anyone who wants
| security updates to move to iOS 26 instead.
| JumpCrisscross wrote:
| The rollback provisions, granted. But I'm arguing the
| other stuff requires QC attention Apple may not want to
| provide to a legacy line. That isn't not allowing
| something that can be done. It's not building something
| they don't want to.
| zzrrt wrote:
| To be fair, it would cost them more to fully test the iOS
| 18 patches on all devices, than what it cost them to test a
| few devices. So I wouldn't quite call it artificially
| holding the patches back. But yeah, it is probably mostly
| motivated by avoiding bad PR of letting slightly-older
| devices get hacked, and then forcing everyone else to be on
| the new release. (FWIW I'm running iOS 18 on an iPhone SE
| 2020, so probably going to have to embrace all the change
| and bugs in iOS 26.)
| lynndotpy wrote:
| No. Apple already released the patch in February, and Apple
| chose not not patch older releases.
|
| Apple of 2026 is not the same Apple of 2025. The people at
| Apple have held back iOS 18.7.3, iOS 18.7.4, iOS 18.7.5, or
| iOS 18.7.6 for most iPhones that support iOS 18.
|
| These are dozens of CVEs patched in these updates, including
| numerous exploits as bad or worse than the one described in
| this one. (Article is paywalled so I couldn't read it, so I
| am getting the details from Google's post
| https://cloud.google.com/blog/topics/threat-
| intelligence/dar...
|
| - CVE-2025-43541, CVE-2025-43501 WebKit zero day https://www.
| theregister.com/2025/12/15/apple_follows_google_... (iOS
| 18.7.3)
|
| - CVE-2025-43529 and CVE-2025-14174, mentioned in the article
| (iOS 18.7.3)
|
| - The dyld exploit fixed in iOS 18.7.5, and the exploit in
| this article
| https://www.theregister.com/2026/02/12/apple_ios_263/ (iOS
| 18.7.5)
|
| Unfortunately, in iOS 26, there is a new bug where Lockdown
| Mode breaks call recording, which is something I rely on.
| Something to weigh for anyone on iOS 18 who is considering
| installing iOS 26.
| walterbell wrote:
| _> Lockdown Mode breaks call recording_
|
| Do you mean screen recording? What are the symptoms of the
| bug?
| lynndotpy wrote:
| Nope, call recording. Not sure how universal this is, but
| phone call recording immediately stops with the "This
| call is no longer being recorded" effect afterwards.
| msk-lywenn wrote:
| Apple is probably going to issue an update for 18. Heck they
| released a security update for coruna on 15.x last week. Same
| thing maybe?
| lynndotpy wrote:
| No, they are not. Apple is choosing to only release the iOS
| 18 security patches for the XS and XR.
| dhosek wrote:
| Liquid glass isn't too bad on the iPhone or even the iPad. It's
| mostly on the Mac that it sucks.
| neom wrote:
| I thought the same thing but updated couple weeks back and
| actually really really enjoy the liquid glass. I don't recall
| what it was about the release that made me think I'd hate it,
| but I've half fallen in love with it, I was just thinking
| yesterday I wonder what all the fuss was about.
| Analemma_ wrote:
| I don't like it on the iPhone, but it's more a "sigh, I'll
| live with it" downgrade than a catastrophic one (at least
| once you go into the Safari settings and turn off the huge
| useless address bar by putting it in compact mode). It's on
| the Mac where it's truly a shitshow.
| thejazzman wrote:
| I believe it's changed a lot since it was initially debut'd
| via the betas. And there was that Supabase post mocking it,
| where they made the whole UI glass, and that biased me a bit
| ha
| k2enemy wrote:
| I'm really hoping Apple backtracks on its refusal to update the
| 18.x line for phones that are compatible with 26. At least
| provide a security update.
| kace91 wrote:
| Their design disaster must be hidden in metrics, damn be
| security.
| lynndotpy wrote:
| Apple used to have a really good security record, it's mind
| boggling they blew it all up just to force Liquid Glass on
| users.
|
| For those not in the loop, Apple used to provide security
| patches for supported older iOS versions. They changed a lot of
| behavior around the release of Liquid Glass (iOS 26, MacOS
| Tahoe). Starting with iOS 18.7.3, they only release patch
| versions for the iPhone XS and XR. They've repeated this,
| through to 18.7.6 now.
|
| So much goodwill and trust, obliterated.
| walterbell wrote:
| _> Starting with iOS 18.7.3, they only release patch versions
| for the iPhone XS and XR. They 've repeated this, through to
| 18.7.6 now._ iPhone XS/XR: the only Usable +
| Secure iPhone in 2026
| yborg wrote:
| It's especially glaring since Apple just released a fix for a
| Coruna exploit that patched iOS 15.
| titzer wrote:
| Those trillions of dollars aren't going to find their way
| into the pockets of the shareholders if they have to pay some
| rubes to maintain old stuff!
| 6510 wrote:
| I'm always surprised what isn't a national security issue.
| walterbell wrote:
| _> to pay some rubes to maintain old stuff_
|
| Can LLMs backport fixes to stable branches?
| lynndotpy wrote:
| Well, Apple already fixed the code, Apple is just
| choosing not to release it for most iPhones.
| floralhangnail wrote:
| That's interesting, as they released security patches for iOS
| 15 devices like iPhone 6 as recent as a week ago.
| fortran77 wrote:
| Apple was always defeated in every pwn2own competition. I'm
| not sure if their security is any better or worse than anyone
| else.
| pfortuny wrote:
| Not going to happen (despite my still being on 18.x) because
| they want to force you to upgrade to 26 for publicity. As
| simple as that.
|
| The new "security upgrade available" will (I bet) be "to 26".
| JumpCrisscross wrote:
| > _for publicity_
|
| Or don't want to maintain two different security
| architectures.
| pfortuny wrote:
| They security-updated iOS 15 a couple of months ago, so
| that does not seem likely.
| JumpCrisscross wrote:
| > _for publicity_
|
| Or don't want to maintain two different security
| architectures. Apple has always been visually opinionated.
| pfortuny wrote:
| They security-updated iOS 15 a couple of months ago, so
| that does not seem likely.
| varispeed wrote:
| Apple should stop doing security by obscurity in the first
| place. People have no way finding out whether their phones have
| been compromised. Lockdown mode is just a cope mechanism for
| phones likely already compromised and there is no guarantee
| lockdown mode cannot be bypassed.
|
| Apple hardware is inherently insecure and it is bizarre that
| Apple keeps burying their head in the sand.
| unsupp0rted wrote:
| Aren't their devices the most secure on the mass market?
|
| More than non-obscure phones, laptops, desktops... washing
| machines, robot vacuums, doorbells, you name it
| varispeed wrote:
| Yes, but you can use anti-virus software on other platforms
| which can detect many threats.
|
| Also just because others are not great, doesn't excuse
| Apple from being very much negligent.
|
| I know many people who bought Apple products specifically
| because of the myth that they are secure. They were in fact
| mis sold. There is common thinking that no anti virus
| software = no viruses = secure among non technical crowd.
| walterbell wrote:
| _> the most secure_
|
| Except for withholding iOS 18 security fixes when public
| exploits are fixed in iOS 26.
| unsupp0rted wrote:
| Even then. I'll take a leaky iOS 18 over pretty much any
| leaky Android or internet-connected TV or whatever.
|
| iPhones are still the least bad option, for regular
| people who aren't planning to solder anything, select
| their boot loader on launch, or recompile a kernel.
| buggeryorkshire wrote:
| My Pixel 8 Pro is more secure than your iOS 18 handset
| Apple don't care about.
| hnburnsy wrote:
| >We also identified additional code added when the actor attempts
| to infect a user using Chrome, where the x-safari-https protocol
| handler is used to open the page in Safari (Figure 4). This
| suggests that UNC6748 didn't have an exploit chain for Chrome at
| the time of this activity.
|
| Thanks Apple for allowing the overriding of the user's default
| browser.
| MrDOS wrote:
| I wish I had a better sense of how these zero-click
| vulnerabilities work so I could get a sense of how to protect
| myself from them (you know, _without_ giving in to Liquid Glass).
| Can they be blocked by an ad blocker? _Are_ they blocked by any
| extant ad blockers? What about "Lockdown Mode"?
| bix6 wrote:
| My understand is ad blockers only stop one class. Lockdown Mode
| is supposedly a major upgrade given all the underlying
| processes it blocks / slows.
| fn-mote wrote:
| Note that this is 1-click.
|
| 0-click example: receive an MMS with a malformed image that
| exploits a bug in decoding
| rsync wrote:
| "0-click example: receive an MMS with a malformed image that
| exploits a bug in decoding ..."
|
| Consider a SMS firewall that:
|
| - flattens text to ascii-256
|
| - recompresses, noises and slightly resizes images and video
|
| ... and only then passes the message onto your real (SIM
| card) phone number.
|
| This, of course, requires that you host your phone number
| somewhere like Twilio which has other added benefits like
| additional protection from SIM-jacking and being invulnerable
| to theft or loss of your handset, etc.
|
| Recommended.
| SimianSci wrote:
| It's a watering hole attack. At any point your iphone sends an
| http request to a compromised site, by add, link, embedded,
| etc. your device will be exploited. there really isn't a way to
| permanently defeat this. We are about to see an explosion of
| novel attack types utilizing this exploit as their basis, you
| realistically cannot defend yourself against these without
| either updating or no longer using an iphone.
| MrDOS wrote:
| What are you talking about?
|
| Why are we about to see an explosion?
| walterbell wrote:
| _> At any point your iphone sends an http request to a
| compromised site, by add, link, embedded, etc. your device
| will be exploited._
|
| Would it help to disable Javascript on untrusted sites via
| Brave?
| throwaway2016a wrote:
| I was literally just attending a course on "innovation" and the
| topic of Apple vs Android was covered. Interestingly enough, a
| majority of students commenting cited iOS "security" as a core
| value proposition. As an Android user, however, I know there are
| a lot of CVEs in volume but in terms of severity, when an iOS
| issue happens it appears to generally be much more severe.
| eugenekolo wrote:
| It's actually a fascinating find by Lookout, iVerify, and Google.
| This is a multi million dollar exploit chain sold to various
| buyers.
|
| Complete full chain 1-click exploit from Safari to complete
| device take over exfiltrating personal data, passwords, and
| crypto wallets.
|
| https://www.lookout.com/threat-intelligence/article/darkswor...
|
| https://iverify.io/blog/darksword-ios-exploit-kit-explained
|
| https://cloud.google.com/blog/topics/threat-intelligence/dar...
| walterbell wrote:
| Is the full exploit chain functional on iPhone 17 MIE/EMTE
| silicon with Lockdown Mode enabled?
| eugenekolo wrote:
| No, because Lockdown Mode disabled JIT which is a part of this
| exploit chain.
| kevincloudsec wrote:
| the supply chain for offensive tooling is now indistinguishable
| from the supply chain for malware. take care of your security
| team!
| geuis wrote:
| I'd like a security patch for 18. I have no desire to upgrade to
| iOS Vista or whatever it is we're calling it
| SayThatSh wrote:
| All these exploits and we still can't get proper jailbreaks on
| new iOS versions :( I moved away from Android years ago in the
| interest of digital privacy so it's just wonderful to hear
| security isn't as tight as I'd hoped haha.. Then again I guess
| those like myself staying on the bleeding edge version-wise
| aren't affected.
| eugenekolo wrote:
| I suspect you'll see one with this or Coruna soon enough.
| DavideNL wrote:
| https://support.apple.com/en-us/126604
|
| _iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), macOS
| 26.3.2 (a)_
|
| _Released March 17, 2026_
|
| _WebKit_
|
| _Available for: iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, macOS
| 26.3.2_
|
| _Impact: Processing maliciously crafted web content may bypass
| Same Origin Policy_
|
| _Description: A cross-origin issue in the Navigation API was
| addressed with improved input validation._
|
| _WebKit Bugzilla: 306050_
|
| _CVE-2026-20643: Thomas Espach_
___________________________________________________________________
(page generated 2026-03-18 23:01 UTC)