Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
SlowMist warns Darksword exploit may target crypto wallets on iOS 26.5
00

SlowMist warns Darksword exploit may target crypto wallets on iOS 26.5

Sep 21, 2026

SlowMist CISO 23pds warns that the Darksword exploit chain, which combines six vulnerabilities to bypass Apple's security controls, may have been adapted to target devices running iOS 26.5. Originally documented by Google as effective against iOS 18.4 through 18.7, the exploit initiates via malicious Safari links to gain root-level control and extract private keys from self-custody crypto wallets. Though the iOS 26.5 exposure remains unconfirmed by Apple or Google, users are urged to update their devices immediately.

Darksword iOS exploit chain

  • ▪Google Threat Intelligence Group identified Darksword as a full iOS exploit chain combining six vulnerabilities to compromise devices and deliver malicious payloads.
  • ▪SlowMist Chief Information Security Officer 23pds warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5.
  • ▪Google Threat Intelligence Group tracked Darksword activity from at least December 2025 through March 2026, linking Darksword operations to victims in Saudi Arabia, Turkey, Malaysia, and Ukraine

Safari-based attack delivery method

  • ▪Attacks using the Darksword exploit chain begin when an iPhone user opens a malicious link in Safari, which is typically delivered through social engineering on social networks or messaging apps
  • ▪The Safari-based Darksword exploit documented by Google Threat Intelligence Group attempts to compromise the browser and other iOS components without requiring the user to install a conventional application

Private key theft from wallets

  • ▪Once the Darksword exploit chain, first documented by Google, succeeds, attackers can obtain root-level control, removing the isolation that prevents one application from reading files belonging to another
  • ▪Root-level control gained via Darksword allows attackers to extract private keys, wallet recovery phrases, and other sensitive data from locally installed self-custody cryptocurrency wallets.

iOS version vulnerability scope

  • ▪Google Threat Intelligence Group documented that the original Darksword framework supported iOS versions 18.4 through 18.7.
  • ▪The Darksword exposure on iOS 26.5 reported by SlowMist has not been independently or officially confirmed by Apple or Google

Security recommendations for users

  • ▪Google and Apple treat keeping mobile software updated as a central defense because Apple has patched the six vulnerabilities documented in the original Darksword chain.
  • ▪SlowMist advised mobile users to install operating-system updates promptly and avoid opening unsolicited links sent by strangers on social media or messaging apps.

Apple patches for vulnerabilities

  • ▪Apple patched CVE-2025-43529, a JavaScriptCore vulnerability used in Darksword against iOS 18.6 and 18.7 devices, in iOS 18.7.3 and iOS 26.2 after Google reported it.
  • ▪Apple has patched all six vulnerabilities documented in the original Darksword exploit chain identified by Google Threat Intelligence Group

2 sources

Crypto
SlowMist warns Darksword may target wallets on iOS 26.5
View source article
News
Slowmist Warns Darksword iOS Exploit Targets Crypto Wallet Keys
View source article

Story comments

Loading comments…

Related Projects

SlowMist

Topics

Bitcoin wallets & custodyCrypto privacy & surveillanceDeFi security vulnerabilitiesCrypto security