Apple Backports iOS 18 Patches for DarkSword Exploit

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Apple will issue iOS 18 patches Wednesday morning against the DarkSword hacking technique, which can silently compromise iPhones that visit malicious websites—a rare "backporting" move the company has historically resisted in favor of pushing users to the latest OS.
- DarkSword was disclosed roughly two weeks ago by researchers at Google, iVerify, and Lookout, and has been used against iPhone users in Malaysia, Saudi Arabia, Turkey, and Ukraine; the tool was posted to GitHub last week, prompting security firms Malfors and Proofpoint to warn that an FSB-linked Russian group is now distributing it via phishing emails.
- iVerify cofounder Rocky Cole said some of the estimated quarter of iPhone users still on iOS 18 as of February are running app versions incompatible with newer OSes, while UK users have resisted iOS 26's age verification features and others lacked storage space to upgrade.
- Patrick Wardle, a former NSA hacker and CEO of Apple-focused security firm DoubleYou, called the backport "better-late-than-never" but said "if protecting users actually matters, backporting critical fixes should be standard, not the exception."
- iOS 18 holdouts cited the unpopularity of iOS 26's "liquid glass" interface on Reddit, with one user writing "Apple is trying to force you onto the dumpster fire that is liquid glass" and another refusing to update from iOS 18.1.1.
- This is the second backport in a month: Apple also pushed iOS 17 patches in March for the Coruna toolkit, which Google and iVerify researchers said spread from Russian espionage hackers to profit-focused cybercriminals and was likely created for the U.S. government.
Why it matters: Roughly a quarter of iPhone users were still on iOS 18 in February—many by deliberate choice over iOS 26's "liquid glass" redesign—leaving millions exposed to DarkSword while Apple initially only patched hardware-incompatible devices. Two backports in a single month suggest Apple is shifting away from a strict "update-or-else" security posture that has defined its patching philosophy for years.


