{"id":11454,"date":"2026-03-19T10:03:35","date_gmt":"2026-03-19T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/19\/new-ios-exploit-with-advanced-iphone-hacking-tools-attacking-users-to-steal-personal-data\/"},"modified":"2026-03-19T10:03:35","modified_gmt":"2026-03-19T10:03:35","slug":"new-ios-exploit-with-advanced-iphone-hacking-tools-attacking-users-to-steal-personal-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/19\/new-ios-exploit-with-advanced-iphone-hacking-tools-attacking-users-to-steal-personal-data\/","title":{"rendered":"New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data"},"content":{"rendered":"<p>    New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated full-chain iOS exploit kit dubbed\u00a0DarkSword, actively deployed by multiple commercial surveillance vendors and state-sponsored threat actors since at least November 2025 to steal sensitive personal data from iPhone users across four countries.<\/p>\n<p>DarkSword is a full-chain iOS exploit that chains six distinct vulnerabilities, four of which were leveraged as zero-days, to achieve complete device compromise on iPhones running iOS versions 18.4 through 18.7.<\/p>\n<p>The exploit chain operates entirely in JavaScript, allowing attackers to bypass Apple\u2019s Page Protection Layer (PPL) and Secure Page Table Monitor (SPTM) mitigations that would otherwise block unsigned native binary code from executing.<\/p>\n<p>GTIG, iVerify, and Lookout analyzed the exploit chain\u2019s name based on toolmarks embedded in recovered payloads and have confirmed its use in targeted campaigns against victims in Saudi Arabia, Turkey, Malaysia, and Ukraine.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-six-vulnerability-ios-exploit-chain\"><strong>Six-Vulnerability iOS Exploit Chain<\/strong><\/h2>\n<p>The six-vulnerability chain begins with a remote code execution (RCE) exploit targeting JavaScriptCore, Apple\u2019s JavaScript engine used in Safari and WebKit, and progresses through two sandbox escape stages, a local privilege escalation, and a final payload deployment that grants attackers full kernel-level privileges.<\/p>\n<p>CVE-2026-20700, a Pointer Authentication Code (PAC) bypass in Apple\u2019s\u00a0<code>dyld<\/code>\u00a0dynamic linker, was chained directly with both RCE exploits and patched only with iOS 26.3 after GTIG reported it to Apple<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Exploit Module<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Vulnerability Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Affected Component<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Zero-Day<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Patched In<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-31277<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>rce_module.js<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">JIT optimization \/ type confusion<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">JavaScriptCore (WebKit)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">No<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS 18.6<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-43529<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">\n<code>rce_worker_18.6.js<\/code>, <code>rce_worker_18.7.js<\/code>\n<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Use-after-free \/ garbage collection bug in DFG JIT layer<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">JavaScriptCore (WebKit)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Yes<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS 18.7.3, 26.2 \u200b<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2026-20700<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">\n<code>rce_worker_18.4.js<\/code>, <code>rce_worker_18.6.js<\/code>, <code>rce_worker_18.7.js<\/code>\n<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Memory corruption \/ user-mode PAC bypass<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">\n<code>dyld<\/code> (Dynamic Linker)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Yes<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS 26.3 \u200b<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-14174<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">\n<code>sbox0_main_18.4.js<\/code>, <code>sbx0_main.js<\/code>\n<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Out-of-bounds memory access in WebGL operation<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">ANGLE (GPU process \/ WebKit)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Yes<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS 18.7.3, 26.2 \u200b<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-43510<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>sbx1_main.js<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Memory management \/ copy-on-write bug<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">XNU Kernel<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">No<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS 18.7.2, 26.1<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-43520<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>pe_main.js<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Kernel-mode race condition in VFS implementation<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">XNU Kernel (Virtual Filesystem)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">No<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS 18.7.2, 26.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>GTIG identified three distinct post-exploitation malware families deployed after a successful DarkSword compromise, each tailored to specific threat actor needs.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhWqNkBAVW4de6ge8_3Vrz_3vB0AqwrqFdgULkZQjv9PWJIYkq25sG_Mx3P-HQId6J0M6VzhQoyVNTeBb0-VWHwcsNYDZYRafErqdheXO3QxmyX83XH4Ytnz6D4uir0xCRoIMXKMYNezzpSlHqYK_H3AQ-BPWmR8hVA5RlWFjyeXOGYuEcaPr_Sym6GnXNp\/s16000\/Exploit%2520chain.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack Chain (Source: Google)<\/figcaption><\/figure>\n<\/div>\n<p>GHOSTKNIFE, deployed by threat cluster UNC6748 via a Snapchat-themed phishing site (<code>snapshare[.]chat<\/code>), is a JavaScript backdoor capable of exfiltrating signed-in accounts, messages, browser data, location history, and audio recordings from the device\u2019s microphone.<\/p>\n<p>It communicates with its <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control (C2) server<\/a> over a custom binary protocol encrypted with ECDH and AES, and actively deletes crash logs from the device to evade forensic detection.<\/p>\n<p>GHOSTSABER, deployed by Turkish commercial surveillance vendor PARS Defense in campaigns targeting Turkey and Malaysia, supports over 15 distinct C2 commands, including device enumeration, file exfiltration, arbitrary SQLite query execution, and photo thumbnail uploads.<\/p>\n<p>Several GHOSTSABER commands, including audio recording and real-time geolocation, are not yet fully implemented in the JavaScript implant itself, suggesting follow-on binary modules are downloaded at runtime from the C2 server.<\/p>\n<p>GHOSTBLADE, attributed to suspected Russian espionage actor UNC6353, functions as a comprehensive data miner exfiltrating iMessages, Telegram, and WhatsApp data, cryptocurrency wallet data, Safari history and cookies, Health databases, device keychains, location history, and saved Wi-Fi passwords.<\/p>\n<p>Unlike the other two families, GHOSTBLADE does not operate persistently or support interactive backdoor commands, but its breadth of data collection makes it highly valuable for intelligence-gathering operations. Notably, GHOSTBLADE\u2019s library code contains a reference to a function named <code>startSandworm()<\/code> that remains unimplemented \u2014 possibly a codename for a separate, forthcoming exploit.<\/p>\n<p>UNC6748 delivered DarkSword through a fraudulent Snapchat lookalike site, using obfuscated JavaScript loaders with anti-debugging protections and session storage fingerprinting to avoid re-infecting the same victims.<\/p>\n<p>PARS Defense upgraded its delivery mechanism to encrypt exploit stages using ECDH key exchange between the attacker infrastructure and the victim device, demonstrating heightened operational security awareness.<\/p>\n<p>UNC6353 \u2014 a suspected Russian espionage group previously linked to the Coruna iOS exploit kit, embedded malicious\u00a0<code>&lt;script&gt;<\/code>\u00a0tags into compromised Ukrainian websites, loading DarkSword silently via hidden iFrames.<\/p>\n<p>Tellingly, a comment in UNC6353\u2019s source code was written in Russian, and GTIG has been working with CERT-UA to mitigate this ongoing campaign active through March 2026.<\/p>\n<p><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/darksword-ios-exploit-chain\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GTIG reported all<\/a> DarkSword vulnerabilities to Apple in late 2025, and all six CVEs have since been patched the majority prior to, and the remainder with the release of\u00a0iOS 26.3.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi8epofw9E2BQ3OE20K6uE7k15ZURzO8pJvVQdZImF78hZ9GDSoYQ_LmsjnQMr1dcjbeeQgxGayl-2zd5Wzs3-vpYvTlMVLOWVXqf1Tg6HvN1I6IWfsc0IkMm4fU2OnDNNFu68Dq01pc4QWVsTvUnqmv-I4UG6OY5dYiHS5_fI_Zo6iz0FeFPRDJBc8Fp4-\/s16000\/Attack%2520Timeline%2520%281%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack Timeline (Source: Google)<\/figcaption><\/figure>\n<p>Google has also added all identified DarkSword delivery domains to Safe Browsing. Users are strongly urged to update to the latest version of iOS immediately; if updates are not available, enabling\u00a0Lockdown Mode\u00a0is recommended as an additional safeguard against this class of exploit.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/darksword-ios-exploit\/\">New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/darksword-ios-exploit\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data A sophisticated full-chain iOS exploit kit dubbed\u00a0DarkSword, actively deployed by multiple commercial surveillance vendors and state-sponsored threat actors since at least November 2025 to steal sensitive personal data from iPhone users across four countries. DarkSword is a full-chain iOS exploit that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-11454","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11454"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11454"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11454\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}