VulnerabilitiesHIGH

DarkSword Exploit - Apple Loosens Patching Policy for iOS

Featured image for DarkSword Exploit - Apple Loosens Patching Policy for iOS
HNHelp Net Security
DarkSwordiOS 18Applesecurity updateCoruna
🎯

Basically, Apple is giving older iPhones security updates to fix a serious problem.

Quick Summary

Apple has changed its patching policy to extend security updates for iOS 18 users. This affects many devices still on older versions. It's crucial to update to stay safe from the DarkSword exploit.

What Happened

Apple has recently made a significant change to its security update policy due to the DarkSword exploit kit. On April 1, 2026, the company announced that it would extend security updates to a broader range of devices still running iOS 18. This decision aims to protect users from vulnerabilities that the DarkSword exploit could exploit.

Who's Affected

The update affects a wide array of devices, including:

  • iPhone XR, XS, and XS Max
  • iPhone 11, 12, 13, 14, 15, and 16 (all models)
  • iPhone SE (2nd and 3rd generation)
  • iPad mini (5th generation)
  • Various models of iPad Air and iPad Pro

This move is particularly important as many users opted to remain on older iOS versions due to dissatisfaction with the interface changes in iOS 26.

What Data Was Exposed

Apple has warned that if users click on malicious links or visit compromised websites while using older iOS versions, their data could be at risk of theft. This makes the DarkSword exploit particularly dangerous, as it could potentially compromise sensitive information stored on these devices.

What You Should Do

Apple emphasizes the importance of keeping software up to date. Users with Automatic Updates enabled will receive these crucial security protections automatically. Here are some steps users should take:

  • Ensure Automatic Updates are turned on.
  • Regularly check for updates manually if Automatic Updates are off.
  • Consider enabling Lockdown Mode for additional protection, even on outdated software.

By taking these actions, users can significantly reduce the risk of falling victim to attacks leveraging the DarkSword exploit.

Conclusion

This policy shift by Apple marks a notable change in its approach to security, reflecting the growing threats posed by exploit kits like DarkSword. By extending support for older devices, Apple aims to protect a larger user base while encouraging timely updates to maintain device security.

🔒 Pro insight: Apple's decision to backport security updates indicates a growing recognition of the risks posed by legacy systems in a rapidly evolving threat landscape.

Original article from

HNHelp Net Security· Sinisa Markovic
Read Full Article

Related Pings

CRITICALVulnerabilities

Cisco Smart Software Manager Vulnerability - Critical Flaw Exposed

Cisco has alerted users about a critical vulnerability in its Smart Software Manager. This flaw allows attackers to execute commands remotely, affecting many organizations. Immediate software upgrades are essential to mitigate risks.

Cyber Security News·
CRITICALVulnerabilities

PX4 Autopilot Vulnerability - Attackers Can Control Drones

A critical vulnerability in PX4 Autopilot software allows attackers to gain full control over drones. This flaw poses serious risks to critical infrastructure. CISA has issued urgent recommendations for operators to secure their systems.

Cyber Security News·
HIGHVulnerabilities

TrueConf Zero-Day Vulnerability - Malware Delivery Exploit

A zero-day vulnerability in TrueConf allows attackers to deliver malware through fake updates. Southeast Asian government networks are particularly at risk. Organizations must act quickly to patch this vulnerability and secure their systems.

Help Net Security·
HIGHVulnerabilities

F5 BIG-IP APM - Over 14,000 Instances Exposed to RCE Attacks

A critical RCE vulnerability exposes over 14,000 F5 BIG-IP APM instances. Organizations must act quickly to secure their systems against potential attacks. F5 has issued guidance to help mitigate risks.

BleepingComputer·
HIGHVulnerabilities

iOS 18.7.7 Update - Apple Expands to Block DarkSword Exploit

Apple has expanded the iOS 18.7.7 update to more devices. This update addresses the DarkSword exploit, which poses significant risks to older devices. Users are urged to enable auto-updates for vital security protections.

The Hacker News·
CRITICALVulnerabilities

Cisco IMC Vulnerability - Critical Authentication Bypass Flaw

Cisco has disclosed a critical authentication bypass vulnerability in its Integrated Management Controller (IMC), allowing attackers to gain administrative access. Urgent updates are now available to mitigate this risk.

Cyber Security News·