Safari zero-day exploit chain linked to leaked "DarkSword" malware
Security & Exploits ·
Security researchers are warning that a remote code execution flaw in iPhone Safari can be triggered by a single click on a malicious link, exposing crypto private keys, seed phrases and keychain data stored on the device.
The warning centers on a leaked attack program called DarkSword, which researchers say is already being exploited in the wild. According to a report attributed to a Chinese security researcher and SlowMist CISO, the tool's core function is pulling forensic-level data off iOS devices through HTTP interfaces, then uploading it to servers controlled by attackers. The same material describes attackers pairing this capability with social engineering or watering-hole tactics to lure victims into clicking a compromised link, at which point passwords, crypto holdings and other stored data on the iPhone or iPad can be extracted.
Apple is said to have already patched the underlying vulnerability, with the affected window originally identified as iOS versions 18.4 through 18.7. However, unconfirmed reports now suggest the exploit may reach beyond that range, potentially affecting even the most current iOS builds, a claim researchers describe as still pending confirmation.
The exploit chain's danger for crypto holders lies in its reach into keychain data, the system store where iPhones often keep credentials and, for some users, wallet-related secrets such as seed phrases and private keys. If forensic-level extraction is possible simply by luring a user to a malicious webpage, no additional malware installation or user download appears necessary beyond the initial click, according to the description of the DarkSword program.
Coverage of the leak is still limited, with two distinct sources currently reporting on the cluster, and the exact scope of vulnerable iOS versions remains unresolved. Also unclear is which specific crypto wallets or apps have been confirmed as targets, or whether Apple has issued or plans a further patch addressing the broader version range now under suspicion. Until that confirmation arrives, the guidance circulating alongside the reports is to update iPhones immediately and treat unsolicited links with added caution.