Rare iPhone Spyware Can Infect Devices With a Single Website Visit, Researchers Say

Researchers say DarkSword can hack an iPhone through Safari after a single visit to a compromised website.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 19 March 2026 13:42 IST
Highlights
  • Google says DarkSword used multiple iOS flaws in one exploit chain
  • The spyware was designed to steal messages, passwords, and photos
  • Apple is said to have patched the bugs across several iOS releases

DarkSword used Safari, GPU, and kernel exploits to move from a website visit to full iPhone compromise

Photo Credit: Unsplash/Norwood Themes

A newly documented iPhone spyware tool is said to compromise a device simply through a visit to a hacked website. As per security researchers, the toolkit, dubbed DarkSword, was used in campaigns targeting people in Ukraine and relies on a chain of exploits that lets attackers break into Safari, escape its security layers, gain deeper access to iOS, steal data, and then remove themselves within minutes. The spyware is said to only target iPhones running specific versions of iOS 18. Apple is said to have patched the vulnerabilities.

New Dangerous iPhone Spyware Discovered

Google Threat Intelligence Group (GTIG), in partnership with Lookout and iVerify, identified a new iOS full-chain exploit which leveraged multiple zero-day (undiscovered) vulnerabilities to completely compromise devices. Notably, a full-chain exploit means the toolkit links together several bugs to move from a web page to full control of the phone.

Advertisement

In this case, the attack starts in JavaScriptCore, the engine used by Safari and WebKit to run website code. From there, the attackers break out of Safari's sandbox, a security boundary meant to isolate risky web content. It first infects the GPU process and then moves into a more privileged iOS system service called mediaplaybackd. Finally, the chain uses kernel flaws to raise privileges even further and deploy the spyware payload.

Google said the chain used multiple vulnerabilities across Apple's software stack, including memory corruption bugs in JavaScriptCore, a flaw in ANGLE used by Safari's graphics handling, and kernel issues in XNU, the core of iOS. Some of those flaws were exploited as zero-days, meaning attackers used them before fixes were publicly available. The researchers say the relevant fixes were shipped by Apple across iOS 18.6, 18.7.2, 18.7.3, 26.1, 26.2, and 26.3, depending on the bug.

Advertisement

The attack is described as a watering hole campaign. That means attackers compromised websites that their targets were likely to visit, then used those sites to deliver the exploit. Google claimed a suspected Russian espionage group, UNC6353, used DarkSword in watering hole attacks on Ukrainian websites, while TechCrunch reported that the malware was designed to infect anyone who visited certain Ukrainian sites from within the country.

As per the publication, DarkSword was built to steal passwords, photos, browser history, and messages from apps, including WhatsApp and Telegram, along with SMS texts. Researchers also found code aimed at cryptocurrency wallet apps; however, it cannot be said for sure that the main objective behind spreading the spyware was financial gain.

Advertisement

Unlike spyware built for long-term surveillance, DarkSword appears to be designed for a quick smash-and-grab operation. Researchers said its dwell time on a device was likely measured in minutes, just long enough to collect and send data out before disappearing. GTIG also shared code snippets showing efforts to delete crash logs, which would make the intrusion harder to spot.

While it is not easy to block the spyware's attempt to break into a device after it has already been infected, users can minimise the chances of infection by avoiding unfamiliar or high-risk websites, especially in conflict-related or politically sensitive contexts. As per GTIG, the hacker group behind the spyware has also deployed the exploit chain in Saudi Arabia, Turkey, and Malaysia. The total number of infected devices is difficult to gauge.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Border 2, Peaky Blinders: The Immortal Man, Chiraiya, and More
  2. Realme P4 Lite 5G Launched in India With These Specifications
  3. Huawei MatePad SE 11 Set to Launch at This Price in India
  4. OnePlus Nord Buds 4 Pro Launched in India With ANC, Up to 54 Hours of Total Playback Time
  5. Lenovo Legion Y700 Gen 5 Launched With Snapdragon 8 Elite Gen 5 SoC, 9,000mAh Battery
  6. You Can Now Simply Tap to Pause Reels on Instagram
  7. Here Are the Best Laser Printers for Home Printing Needs
  8. OnePlus 15T Will be Launched With These Two Gaming-Focused Features
  9. Here's When the Vivo X300 Ultra and Vivo X300s Will Be Launched
  10. OnePlus Watch 4 Could Launch Soon, Listing on EMVCo Site Hints
  1. Meta’s New Facebook Initiative Offers TikTok, YouTube Creators Increased Reach and Guaranteed Pay
  2. Instagram Rolls Out Tap-to-Pause Feature for Reels With More Control Over Playback
  3. Seetha Payanam Now Streaming on OTT: Where to Watch Arjun Sarja’s Romantic Road Trip Drama
  4. Circle Urges UK to Blend MiCA Clarity With US Stablecoin Rules
  5. OnePlus 15T Confirmed to Launch With Next-Gen Gaming Kernel, Same G2 Wi-Fi Chip as OnePlus 15
  6. OnePlus Watch 4 Reportedly Visits Certification Database Hinting at an Imminent Launch
  7. Lenovo Legion Y700 Gen 5 Gaming Tablet Launched With Snapdragon 8 Elite Gen 5 SoC, 9,000mAh Battery: Price, Features
  8. Kaattaan OTT Release Date Revealed: Know When and Where to Watch Vijay Sethupathi’s Upcoming Thriller Series
  9. Google Pixel Users Report Freezing Issues on Lock Screen, Always-On Display Following March Update
  10. Rare iPhone Spyware Can Infect Devices With a Single Website Visit, Researchers Say
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.