HomeSecurityDarkSword exploit leaked on GitHub

The DarkSword exploit leaked on GitHub

The DarkSword exploit, revealed last week by Google's Threat Intelligence Team, is now publicly available on GitHub, increasing the need to immediately update older iPhones and iPads.

DarkSword GitHub

In recent weeks, Google's Threat Intelligence Team, iVerify, and Lookout have revealed details of two exploits, Coruna and DarkSword, that combine multiple iOS and iPadOS vulnerabilities to compromise older iPhones and iPads.

Both exploits rely on WebKit and other vulnerabilities that Apple recently patched with iOS 16.7.15, iOS 15.8.7, iPadOS 16.7.15, and iPadOS 15.8.7. The combination of security flaws allows attackers to steal user data or gain complete control over a device.

See also: Apple: Old iPhones vulnerable to Coruna and DarkSword exploits

Following the disclosure of the two exploits, Apple published a support document emphasizing the importance of updating devices, even if they cannot run iOS 26 or iPadOS 26. Apple also added that Lockdown Mode can further limit hacking attempts.

DarkSword is an advanced delivery framework that exploits a chain of six vulnerabilities, listed as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520 . These vulnerabilities allow attackers to bypass sandboxes, escalate privileges, and execute remote code on unpatched iPhones. The  latest versions of iOS have already patched these vulnerabilities , limiting the threat to devices running iOS 18.4 through 18.7.

The DarkSword exploit leaked on GitHub

DarkSword exploit on GitHub

Now, as TechCrunch has noticed, a newer version of DarkSword has been leaked and published on GitHub, meaning attacks exploiting these vulnerabilities are likely to increase.

See also: CISA to federal agencies: Protect yourself against DarkSword

Matthias Frielingsdorf, co-founder of iVerify, noted that these new versions share the same infrastructure as the ones previously analyzed, although the files are slightly different. The files uploaded to GitHub are simple, consisting of just HTML and JavaScript, meaning anyone can copy and paste them and host them on a server in no time.

When asked about the leak, Frielingsdorf said, "This is bad. It's very easy to repurpose. I don't think it can be contained anymore. So we should expect criminals and others to start deploying it. The exploits will work straight away. No iOS expertise required."

The DarkSword exploit leaked on GitHub

TechCrunch reached out to Apple and Microsoft (which owns GitHub) about the exploit. While Microsoft did not immediately respond, Apple acknowledged the existence of the exploit, which targets devices running older, outdated operating systems , and issued an emergency update for devices that cannot run recent versions of iOS.

See also: Apple: New iOS and iPadOS updates address Coruna exploit

CISA warning

CISA ordered all US government agencies to patch three critical iOS vulnerabilities, which have been targeted for cryptocurrency theft and espionage via the DarkSword exploit kit.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS