DarkSword iPhone exploit leaked on GitHub

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- DarkSword — A newer version of the iPhone hacking toolkit was published on GitHub, and iVerify co-founder Matthias Frielingsdorf told TechCrunch the exploits are "way too easy to repurpose" and require "no iOS expertise" to deploy.
- Apple — About one-quarter of its 2.5 billion active devices still run iOS 18 or earlier, putting hundreds of millions of iPhones and iPads at risk; the company issued an emergency update on March 11 for devices unable to run recent iOS, and said Lockdown Mode blocks these attacks.
- Google — A spokesperson confirmed its researchers agree with iVerify's assessment that the leaked DarkSword tools are trivially deployable against unpatched Apple devices.
- Security hobbyist matteyeux — Successfully hacked an iPad mini running iOS 18 using the leaked sample, publicly confirming the tool works "out of the box" without modification.
- The leaked code is simple HTML and JavaScript that can be hosted on a server "in a couple minutes to hours," and includes comments describing its ability to exfiltrate contacts, messages, call history, and iOS keychain secrets to a remote server.
Why it matters: The leak puts a government-grade iPhone spyware tool into the hands of any hacker, potentially exposing the roughly 625 million devices (one-quarter of Apple's 2.5 billion active devices) still running iOS 18 or earlier. Apple has issued an emergency update, but the fix only works for users who actually install it — putting the entire mitigation burden on end users.


