
Attackers are chaining WebKit exploits with sandbox escapes to achieve kernel-level access on iOS devices. TRC analysis shows DarkSword uses CVE-2024-23222 and CVE-2023-32409 for initial compromise, then escalates privileges to exfiltrate passwords and crypto wallets. #MobileSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/darksword-ios-exploit-kit-2026
Post summary
The text reports that attackers actively use CVE‑2024‑23222 and CVE‑2023‑32409 in a chained exploit to achieve kernel‑level access on iOS devices, indicating real‑world exploitation.
