A spyware tool identified as ‘DarkSword’ is capable of exploiting vulnerabilities in iOS to gain unauthorised access to iPhones and extract user data through a single interaction, according to security researchers.
The Google Threat Intelligence Group (GTIG), in collaboration with Lookout and iVerify, reported that the iOS spyware ‘DarkSword’ was used in a targeted campaign in Ukraine. The tool exploits vulnerabilities in Safari and WebKit to infiltrate iPhones. It can extract passwords, messages, photos, and browser history. The toolkit is effective on certain versions of iOS 18 and uses a full-chain exploit.
DarkSword uses a full-chain exploit, combining multiple undiscovered vulnerabilities, or zero-day vulnerabilities, to gain complete control of a device. The attack begins in JavaScriptCore, which executes website code in Safari and WebKit. It then propagates through system components including the GPU process and services such as mediaplaybackd, before exploiting kernel-level weaknesses to install the spyware payload. The process occurs without user notification.

The spyware is designed to access data from applications including WhatsApp and Telegram, as well as browser data. It targets passwords, messages, photos, and browsing history, enabling access to personal and sensitive information.
Experts advise iPhone users to keep their devices updated and to open only trusted websites and applications. Avoiding unknown links or potentially malicious websites is identified as a primary security measure.









