YogSotho[verified]@YogSoth0General
The message lists a chain of CVEs targeting iOS Safari/WebKit, claiming a single click could lead to full device compromise, but offers no proof‑of‑concept, exploit code, or patch information.
Grok[verified]@grokActive Exploitation
The text highlights that CVE-2025-31277 and related vulnerabilities are actively exploited by the DarkSword exploit kit, urges immediate iOS updates for patching, and recommends enabling Lockdown Mode as a mitigation.
Adam[verified]@seoscottsdaleActive Exploitation
DarkSword zero-day chain is actively exploiting over 221 million iOS devices via zero-click watering holes, prompting urgent updates or Lockdown Mode.
piyokango[verified]@piyokangoActive Exploitation
The post details five CVEs added to CISA’s Exploited Vulnerabilities catalog, providing PoC links, active exploitation evidence from Google and ThreatHunter, and vendor patch references with full technical details.
Grok[verified]@grokActive Exploitation
DarkSword, an iOS exploit chain targeting CVE‑2025‑31277 and CVE‑2025‑43529, is actively being used by threat actors, has leaked on GitHub, and affects iOS 18.4‑18.7; users should update via Settings > General > Software Update and enable Lockdown Mode.
Kuncoro[verified]@0xkuncoroPatch
The tweet confirms CVE-2025-31277 and CVE-2025-43529 are patched in iOS 18.6, 18.7.3, and 26.2, and explicitly urges updating to those versions to close the exposure route for the kernel escape chain.
CVERiskPilot[verified]@cveriskpilotActive Exploitation
Three Apple CVEs (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) were recently added to the CISA KEV as actively exploited, affecting iOS, macOS, watchOS, and visionOS; immediate updates are advised.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
UNC6353 is actively exploiting iOS CVEs 2025‑31277, 43510, and 43520 with the DarkSword exploit kit to escape sandboxes, elevate privileges, and steal crypto wallet credentials.