CVE-2025-43520Active Exploitation(apple / ipados)

CRITICALCVSS 5.5 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-120

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 18 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 14 observed days

What's happening

  • Active exploitation reported across 18 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 20 signals
  • Disclosure: 5 classified signals
  • Peaked 11d ago at 5 mentions (2026-03-20); latest day: 1
  • 27 total mentions across 14 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

1 version affected across 6 products

Deep dive

Activity timeline27 mentions / 14d
01345Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-20: 5Mentions · 2026-03-21: 3Mentions · 2026-03-22: 1Mentions · 2026-03-23: 4Mentions · 2026-03-24: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 5Mentions · 2026-03-30: 1Mentions · 2026-04-27: 1Mentions · 2026-05-28: 1Mentions · 2026-06-28: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-28: 3PoC Mentioned / Linked · 2026-07-29: 1Exploit Tool / Code · 2026-03-20: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-24: 1Exploit Tool / Code · 2026-03-28: 2Exploit Tool / Code · 2026-03-30: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-20: 3Active Exploitation · 2026-03-21: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 3Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-28: 5Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-05-28: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-20: 3Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-28: 5Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 2Technical Details · 2026-03-23: 4Technical Details · 2026-03-24: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 4Technical Details · 2026-03-30: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-28: 1Technical Details · 2026-07-29: 103-1803-1903-2003-2103-2203-2303-2403-2703-2803-3004-2705-2806-2807-29
Signal classification5 categories
Active Exploitation
1659.3%
Disclosure
518.5%
Patch
27.4%
General
27.4%
Exploit
27.4%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-03-191
Active Exploitation1
2026-03-205
Active Exploitation3Disclosure1Patch1
2026-03-213
Active Exploitation1Disclosure2
2026-03-221
Active Exploitation1
2026-03-234
Active Exploitation3General1
2026-03-241
Active Exploitation1
2026-03-271
Active Exploitation1
2026-03-285
Active Exploitation3Exploit1Patch1
2026-03-301
Active Exploitation1
2026-04-271
General1
2026-05-281
Active Exploitation1
2026-06-281
Exploit1
2026-07-291
Disclosure1
Full discourse20 posts
  • Muirey03@Muirey03
    Active Exploitation

    My analysis of CVE-2025-43520, the kernel vulnerability exploited by DarkSword (patched in 26.1): https://gist.github.com/Muirey03/8c8370258e32bafaf99e72ec90258c8d

    Post summary

    The post confirms CVE-2025-43520 is actively exploited by DarkSword, references a PoC via a gist, and notes the vulnerability is patched in version 26.1, but lacks detailed technical disclosure of the flaw.

    244228913833.1K
    7.3K followersView on X
  • YogSotho@YogSoth0
    Exploit

    #DarkSword #iOS #Exploit Chain — Six-Stage Nuclear Exploit Kit Exploit Chain: CVE-2025-31277 → CVE-2026-20700 → CVE-2025-14174 → CVE-2025-43510 → CVE-2025-43520 Target: iOS 18.4 - 18.7 (#Safari/#WebKit) Effect: Full device compromise from one click (watering hole) Privileges: Root / Kernel-level #0days #security #hacking #root #CVE

    Post summary

    The thread announces a chain of CVEs targeting iOS that supposedly lead to full device compromise in a single click, but it lacks concrete proof of an operational exploit, detailed technical description, or evidence of active exploitation.

    113611988516.2K
    1.9K followersView on X
  • Proteas@ProteasWang
    General

    Some open challenges for AI: 1. exploit the BootROM bug on A13. 2. exploit the SEPROM bug on A11. 3. exploit CVE-2025-43520 to escape the sandbox on A19. 4. ...

    Post summary

    The post lists several AI‑focused challenges, including exploitation of BootROM and SEPROM bugs and a sandbox escape via CVE‑2025‑43520 on device A19.

    81201185013.3K
    6.8K followersView on X
  • Proteas@ProteasWang
    Active Exploitation

    DarkSword-A19: Re-exploited the CVE-2025-43520 (DarkSword) using a pointer-less approach, but the heap spraying part has some issues on iOS. :(

    Post summary

    The post reports that DarkSword-A19 re‑exploited CVE‑2025‑43520 using a pointer‑less method, noting issues with heap spraying on iOS, but does not provide exploit code, patches, or a PoC.

    5701042910.3K
    6.8K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに5件の脆弱性を追加。Apple社複数製品のCVE-2025-31277、CVE-2025-43510、CVE-2025-43520、Craft CMSのCVE-2025-32432、Laravel LivewireのCVE-2025-54068。 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added five CVEs to its catalog of known‑exploited vulnerabilities, indicating these weaknesses are being actively leveraged in real‑world attacks.

    100531.1K
    7.3K followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    ⚠️ @thehackernews nailed it. DarkSword = 6-zero-day iOS full chain (CVE-2025-31277 JSCore + CVE-2025-43520 XNU kernel) compromising 221 million+ unpatched devices (iOS 18.4–18.6.2) via zero-click watering-hole sites. Fileless JS, hit-and-run crypto/credential theft, then self-clean. Update to iOS 18.7.6 or 26.3.1 NOW. Can’t? Enable Lockdown Mode immediately. Who’s still on vulnerable iOS? Drop your version below 👇 #DarkSword #iOSSecurity #ZeroDay #Apple

    Post summary

    The post reports that DarkSword, a 6-zero‑day iOS exploitation chain, has actively compromised over 221 million unpatched devices, providing patch and mitigation guidance.

    02033766
    12.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/20追加) 🛡️No.1548 CVE-2025-31277 Apple Multiple Products Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 8.8 (CVSS Base) / CISA-ADP ・種別:バッファ境界の不適切な制限 (CWE-119) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Apple の複数製品において、悪意ある Web コンテンツの処理によりメモリ破損が発生し得る脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:中 ✅攻撃前提条件 ・被害者が細工された Web コンテンツを処理すること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・メモリ破損 ・任意コード実行の可能性 ・端末侵害の初期侵入点化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が DarkSword での利用を報告。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-31277 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/124147 🛡️No.1549 CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.8 (CVSS Base) / NVD ・種別:不適切なロック (CWE-667) ・CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、プロセス間で共有されるメモリに予期しない変更を生じさせる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・共有メモリの不正変更 ・プロセス間干渉 ・後続の権限奪取やチェーン攻撃の踏み台化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が、DarkSword の GPU サンドボックス脱出段階で使用したと説明。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43510 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125632 🛡️No.1550 CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.1 (CVSS Base) / NVD ・種別:境界外書き込み (CWE-787) / NVD、クラシックバッファオーバーフロー (CWE-120) / CISA-ADP ・CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、予期しないシステム終了やカーネルメモリ書き込みを引き起こされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・システム異常終了 ・カーネルメモリ書き込み ・権限昇格や端末掌握の足掛かり ([NVD][6]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(GTIG が DarkSword の最終段階 `pe_main.js` において、脆弱性を悪用し物理/仮想メモリ でread/write primitive を構築すると説明) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43520 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125633 🛡️No.1551 CVE-2025-32432 Craft CMS Code Injection Vulnerability =================================== ✅概要 ・深刻度:緊急🔥 10.0 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 事前認証されていない攻撃者により、リモートからコード実行される恐れがあります。Craft CMS において、3.0.0-RC1 以上 3.9.15 未満、4.0.0-RC1 以上 4.14.15 未満、5.0.0-RC1 以上 5.6.17 未満が影響を受けます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Craft CMS が外部公開されていること ・脆弱バージョンが稼働していること ・攻撃者は認証不要、ユーザー操作不要 ✅悪用時影響 ・未認証でのリモートコード実行 ・Web サーバ侵害 ・情報窃取 ・Web 改ざんや追加マルウェア設置 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(Craft CMS は 2025-04-17 に “exploited in the wild” を示唆する証拠を確認したと公表) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32432 https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432](https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 🛡️No.1552 CVE-2025-54068 Laravel Livewire Code Injection Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.8 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Livewire v3.0.0 以上 3.6.4 未満において、特定の component property update の hydration 処理に起因。事前認証されていない攻撃者により、特定条件下でリモートからコード実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Livewire v3 系の脆弱バージョンが公開環境で稼働していること ・対象コンポーネントが特定の方法で mounted / configured されていること ✅悪用時影響 ・未認証でのリモートコマンド実行 ・アプリケーションサーバ侵害 ・情報窃取 ・追加マルウェア設置や横展開 ([NVD][7]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(ThreatHunter .ai はイラン系脅威アクターから、CVE-2025-54068 向け custom Nuclei template と 9 confirmed targets を報告) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-54068 https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/ https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added five known exploited CVEs to its catalog, highlighting in‑the‑wild activity, publicly available PoCs or exploit tools, and vendor advisories.

    030414.0K
    42.8K followersView on X
  • T1erOne@tieroneforum
    Disclosure

    Эксплуатация race condition в XNU VFS — произвольное чтение/запись ядра iOS (CVE-2025-43520) https://tier1.life/thread/444 http://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/444 #articles @imnotclarity

    Post summary

    The post discloses a race condition in iOS XNU VFS (CVE‑2025‑43520) allowing arbitrary kernel read/write, providing links to forum threads but no exploit code, patch, or evidence of active exploitation.

    11010181
    270 followersView on X
  • CVERiskPilot@cveriskpilot
    Active Exploitation

    3 Apple CVEs hit the CISA KEV this week — all actively exploited: CVE-2025-31277 (memory corruption) CVE-2025-43510 (DoS) CVE-2025-43520 (buffer overflow) iOS, macOS, watchOS, visionOS affected. Update everything. Today. #Apple #AppSec

    Post summary

    Three Apple CVEs were added to the CISA KEV and are confirmed to be actively exploited across iOS, macOS, watchOS, and visionOS.

    00030150
    13 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows UNC6353 deployed the DarkSword exploit kit to chain iOS vulnerabilities CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520. Attackers escaped sandboxes, escalated privileges, and moved laterally across compromised devices to steal cryptocurrency wallet credentials. #MobileSecurity #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/darksword-ios-exploit-kit-2026-unc6353-crypto-theft

    Post summary

    UNC6353 used the DarkSword exploit kit to chain three iOS CVEs, successfully bypassing sandboxing and escalating privileges to steal cryptocurrency wallet credentials, demonstrating active in‑the‑wild exploitation.

    01010240
    1.9K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性5件をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 20) CVE-2025-31277 Apple複数製品におけるバッファオーバーフローの脆弱性 CVE-2025-32432 Craft CMS コードインジェクションの脆弱性 CVE-2025-43510 Apple複数製品における不適切なロックの脆弱性 CVE-2025-43520 Apple複数製品におけるクラシックバッファオーバーフローの脆弱性 CVE-2025-54068 Laravel Livewireのコードインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added five CVEs, all identified as known exploited vulnerabilities, to its catalog, underscoring active exploitation in the wild.

    00020256
    4.8K followersView on X
  • Adam@seoscottsdale
    Exploit

    🚨 iOS Security 101: Lockdown Mode explained (perfect for DarkSword-level threats) With iOS 26.4 now out, the 6-zero-day DarkSword chain (incl. CVE-2025-31277 + CVE-2025-43520) has been publicly leaked on GitHub. Multiple actors (TA446 etc.) are actively using it. CISA added the CVEs to KEV. Apple is pushing Lock Screen “Critical Software” alerts to vulnerable devices. Not for everyday users — it’s built for high-risk people (journalists, activists, politicians). Normal iOS security handles 99% of threats. 🛡️ When ON, it slashes your device’s attack surface: • Blocks complex web tech in Safari (kills web-based exploits like DarkSword cold) • Most Messages attachments & links disabled • FaceTime incoming calls limited • No new shared Photo albums • No 2G/3G, no auto insecure Wi-Fi • Must unlock to connect accessories/computers • Game Center, Focus, MDM changes blocked Trade-off: Some apps & sites feel broken. Basic calls, texts & SOS still work fine. ✅ Works on iOS 16+, iPadOS 16+, watchOS 10+, macOS Ventura+ How to turn it on (iPhone/iPad): 1. Settings → Privacy & Security 2. Tap Lockdown Mode 3. Turn On & Restart (Your paired Apple Watch auto-enables too) Bottom line: Lockdown Mode stops DarkSword-style Safari attacks cold. With the exploit now public + iOS 26.4 available, high-risk users should enable it TODAY. Everyone else → just update to iOS 26.4 immediately (or 18.7.7 on older hardware). Easy to test & disable anytime. What iOS version are you running? 👇 #iOSSecurity #DarkSword #LockdownMode #CyberSecurity

    Post summary

    The CVE-2025-31277 and CVE-2025-43520 zero-day sequence for DarkSword has been publicly leaked and is actively exploited; Apple recommends Lockdown Mode or an OS update as a mitigation.

    10000407
    12.4K followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    GPU sandbox escape (CVE-2025-43810) & local privilege escalation (CVE-2025-43520) exploit iOS 18.4-18.7 via a malicious Safari page for full kernel control. Various threat actors leveraged this vulnerability. #iOSsecurity

    Post summary

    The text reports that CVE-2025-43810 and CVE-2025-43520 are being actively exploited in the wild on iOS 18.4‑18.7 through malicious Safari pages, enabling full kernel control. No patch or mitigation is mentioned.

    10000112
    4 followersView on X
  • Jugger@kkimjaechu25852
    General

    5/10 Step 5~6 커널 메모리 취약점 CVE-2025-43510 + CVE-2025-43520 → 루트 권한 획득 + PPL/SPTM 완전 우회

    Post summary

    The post describes kernel memory vulnerabilities CVE-2025-43510 and CVE-2025-43520, highlighting their ability to provide root privilege escalation and bypass of PPL/SPTM, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    10000108
    104 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Russian 🇷🇺 UNC6353 deploys "DarkSword" iOS exploit kit targeting crypto wallets and personal data via watering hole attacks. Exploits CVE-2025-31277 through CVE-2025-43520 affecting iOS 18.4-18.7 devices. #DFIR_Radar https://t.co/Bv8ESL3HzZ

    Post summary

    Russian actors UNC6353 have deployed the DarkSword iOS exploit kit, targeting crypto wallet users via watering‑hole attacks and actively exploiting multiple CVEs on iOS 18.4‑18.7 devices.

    1000028
    31 followersView on X
  • Cleus@cleus_ai
    Disclosure

    Darksword hits six main bugs. cve-2025-31277 and cve-2025-43529 are javascript messes that let code run in safari. cve-2026-20700 skips pointer locks for real control. then sandbox breaks with cve-2025-14174 in graphics and cve-2025-43510 kernel copy bug. final kernel grab via cve-2025-43520 race flaw. all super dangerous memory issues with top danger scores, patched in ios 18.7+ and 26.x. those apple and russian flag pics nail it. update asap.

    Post summary

    Darksword announced six critical CVEs, including Safari JavaScript bugs and kernel flaws, that were patched in iOS 18.7+ and 26.x, with no proof‑of‑concept or active exploit evidence disclosed.

    00001184
    434 followersView on X
  • Psychic Lab Ape@psyciclabs
    Active Exploitation

    🚨 Russian APT Star Blizzard deploys DarkSword iOS exploit kit targeting 18.4-18.7. Full-chain: CVE-2025-31277 (JSCore RCE) → CVE-2026-20700 (PAC bypass) → CVE-2025-43520 (kernel privesc). GHOSTKNIFE backdoor exfils in minutes. Update to iOS 26.3+ now. #infosec

    Post summary

    The text reports that the Russian APT Star Blizzard has deployed the DarkSword iOS exploit kit exploiting CVE-2025-31277, CVE-2026-20700, and CVE-2025-43520 on iOS 18.4-18.7, with active attacks ongoing; an iOS 26.3+ update now mitigates the risk.

    00000302
    19 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    Quoting @BleepinComputer on the new DarkSword iOS infostealer exploit: 10 days later and it’s worse. DarkSword chain leaked to GitHub → now in the hands of TA446 + others. CISA just added the 6 zero-days (incl. CVE-2025-31277 & CVE-2025-43520) to Known Exploited Vulnerabilities list. Apple sending lock-screen critical alerts about active attacks. 221M+ unpatched devices still at risk from one Safari visit. Patch to iOS 18.7.6 / 26.3.1 or turn on Lockdown Mode. Full breakdown + IOCs in replies 👇 #DarkSword #CISA #iOS #CyberSecurity

    Post summary

    The tweet reports that DarkSword iOS zero‑day exploits have been leaked to GitHub, are actively used by threat actors, prompting CISA and Apple to issue alerts and urging users to patch or enable Lockdown Mode.

    00000310
    12.4K followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    ⚠️ @BleepinComputer Spot on with the initial DarkSword alert. Latest update (March 28): The full 6-zero-day chain (CVE-2025-31277 JSCore + CVE-2025-43520 XNU kernel) has now been publicly leaked on GitHub. Multiple actors including TA446 are actively deploying it globally. CISA added the CVEs to KEV catalog. Apple is pushing Lock Screen “Critical Software” alerts to vulnerable devices. 221M+ iPhones (iOS 18.4–18.6.2) still exposed via zero-click watering-hole sites. Fileless JS → hit-and-run data theft → self-clean. Update to iOS 18.7.6 or 26.3.1 NOW. Can’t? Enable Lockdown Mode immediately. What iOS version are you on? 👇 #DarkSword #iOSSecurity #ZeroDay #Apple

    Post summary

    The message announces that CVE‑2025‑31277 and CVE‑2025‑43520 have been publicly leaked and are being actively exploited worldwide, prompting Apple to push critical alerts and urging users to update or enable Lockdown Mode for protection.

    00000196
    12.4K followersView on X
  • Adam@seoscottsdale
    Patch

    ⚠️ @BleepinComputer Exactly — CISA ordered to patch DarkSword’s 6-zero-day chain (CVE-2025-31277 JSCore + CVE-2025-43520 XNU kernel). Now TA446 is actively deploying the leaked kit in spear-phishing campaigns targeting gov, academic & policy orgs. 221M+ unpatched devices (iOS 18.4–18.6.2) still exposed via zero-click watering-hole sites. Fileless JS, hit-and-run data theft (crypto/keys/photos), then self-clean. Apple is even pushing lock-screen alerts about these attacks. Federal agencies: enforce the directive NOW. Everyone else: update to iOS 18.7.6 or 26.3.1 immediately. Can’t update? Enable Lockdown Mode. Still on old iOS? Check Settings → General → About 👇 #DarkSword #CISA #iOSSecurity #ZeroDay

    Post summary

    CISA mandates patching for DarkSword zero‑days and notes active exploitation via a leaked kit; users are urged to update immediately or enable Lockdown Mode to mitigate.

    00000218
    12.4K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleipados26.0--
OSappleiphone_os---
OSappleiphone_os26.0--
OSapplemacos---
OSapplemacos26.0--
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more