Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Scheduled Pinned Locked Moved Uncategorized
22 Posts 13 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gknauss@mastodon.socialG gknauss@mastodon.social

    Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

    Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

    jsnell@zeppelin.flightsJ This user is from outside of this forum
    jsnell@zeppelin.flightsJ This user is from outside of this forum
    jsnell@zeppelin.flights
    wrote last edited by
    #3

    @gknauss worse, it’ll patch it, just not for phones that can run 26

    gknauss@mastodon.socialG abdalian@lingo.lolA mirabilos@toot.mirbsd.orgM 3 Replies Last reply
    0
    • gknauss@mastodon.socialG gknauss@mastodon.social

      Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

      Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

      abdalian@lingo.lolA This user is from outside of this forum
      abdalian@lingo.lolA This user is from outside of this forum
      abdalian@lingo.lol
      wrote last edited by
      #4

      @gknauss which are you choosing, Sophie?

      1 Reply Last reply
      0
      • gknauss@mastodon.socialG gknauss@mastodon.social

        Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

        Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

        cynblogger@sfba.socialC This user is from outside of this forum
        cynblogger@sfba.socialC This user is from outside of this forum
        cynblogger@sfba.social
        wrote last edited by
        #5

        @gknauss
        I’ve been one of the very reluctant upgradees to 26, but I bit the bullet last week on iPhone & iPad &…it’s all fine. I even like the (subdued) glass.

        1 Reply Last reply
        0
        • gknauss@mastodon.socialG gknauss@mastodon.social

          Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

          Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.town
          wrote last edited by
          #6

          @gknauss Yes, they would.

          "This vulnerability is completely theoretical."

          1 Reply Last reply
          0
          • gknauss@mastodon.socialG gknauss@mastodon.social

            Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

            Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

            slyborg@vmst.ioS This user is from outside of this forum
            slyborg@vmst.ioS This user is from outside of this forum
            slyborg@vmst.io
            wrote last edited by
            #7

            @gknauss >letting malware hackers force your new UI that people hate on them

            It's a bold strategy Cotton, let's see if it pays off for 'em…

            1 Reply Last reply
            0
            • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

              @gknauss worse, it’ll patch it, just not for phones that can run 26

              gknauss@mastodon.socialG This user is from outside of this forum
              gknauss@mastodon.socialG This user is from outside of this forum
              gknauss@mastodon.social
              wrote last edited by
              #8

              @jsnell If they hasn’t throttled the CPU because of the battery, I’d still be on my iPhone 6.

              AND NOBODY WOULD BE ON MY LAWN.

              1 Reply Last reply
              0
              • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                @gknauss worse, it’ll patch it, just not for phones that can run 26

                abdalian@lingo.lolA This user is from outside of this forum
                abdalian@lingo.lolA This user is from outside of this forum
                abdalian@lingo.lol
                wrote last edited by
                #9

                @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

                ultranurd@tacobelllabs.netU 1 Reply Last reply
                0
                • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                  @gknauss Hey! Do you have a source for this?

                  gknauss@mastodon.socialG This user is from outside of this forum
                  gknauss@mastodon.socialG This user is from outside of this forum
                  gknauss@mastodon.social
                  wrote last edited by
                  #10

                  @mttaggart Nothing explicit, but reading between the lines…

                  iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

                  Link Preview Image
                  Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

                  A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

                  favicon

                  WIRED (www.wired.com)

                  mttaggart@infosec.exchangeM 1 Reply Last reply
                  0
                  • gknauss@mastodon.socialG gknauss@mastodon.social

                    @mttaggart Nothing explicit, but reading between the lines…

                    iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

                    Link Preview Image
                    Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

                    A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

                    favicon

                    WIRED (www.wired.com)

                    mttaggart@infosec.exchangeM This user is from outside of this forum
                    mttaggart@infosec.exchangeM This user is from outside of this forum
                    mttaggart@infosec.exchange
                    wrote last edited by
                    #11

                    @gknauss I think the thing is to move to 18.7.3, which is patched.

                    For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

                    I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

                    Link Preview Image
                    The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

                    DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

                    favicon

                    Google Cloud Blog (cloud.google.com)

                    gknauss@mastodon.socialG 1 Reply Last reply
                    0
                    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                      @gknauss I think the thing is to move to 18.7.3, which is patched.

                      For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

                      I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

                      Link Preview Image
                      The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

                      DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

                      favicon

                      Google Cloud Blog (cloud.google.com)

                      gknauss@mastodon.socialG This user is from outside of this forum
                      gknauss@mastodon.socialG This user is from outside of this forum
                      gknauss@mastodon.social
                      wrote last edited by
                      #12

                      @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                      mttaggart@infosec.exchangeM misty@digipres.clubM 2 Replies Last reply
                      0
                      • gknauss@mastodon.socialG gknauss@mastodon.social

                        @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                        mttaggart@infosec.exchangeM This user is from outside of this forum
                        mttaggart@infosec.exchangeM This user is from outside of this forum
                        mttaggart@infosec.exchange
                        wrote last edited by
                        #13

                        @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                        mirabilos@toot.mirbsd.orgM 1 Reply Last reply
                        0
                        • abdalian@lingo.lolA abdalian@lingo.lol

                          @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

                          ultranurd@tacobelllabs.netU This user is from outside of this forum
                          ultranurd@tacobelllabs.netU This user is from outside of this forum
                          ultranurd@tacobelllabs.net
                          wrote last edited by
                          #14

                          @abdalian @jsnell @gknauss I'm kinda surprised more enterprise phone fleets (that haven't updated their apps for 26 yet) aren't screaming about this

                          1 Reply Last reply
                          0
                          • gknauss@mastodon.socialG gknauss@mastodon.social

                            Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                            Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                            K This user is from outside of this forum
                            K This user is from outside of this forum
                            ke7zum@glitchsoc.bg-presents.us
                            wrote last edited by
                            #15

                            @gknauss I have to agree. there was a patch that went very, very wrong in windows 11 this patch tuesday. Or was it last month? anyway MS just released a fix last week. Taht was indeed fast.

                            1 Reply Last reply
                            0
                            • gknauss@mastodon.socialG gknauss@mastodon.social

                              Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                              Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                              fmarini@mastodon.socialF This user is from outside of this forum
                              fmarini@mastodon.socialF This user is from outside of this forum
                              fmarini@mastodon.social
                              wrote last edited by
                              #16

                              @gknauss https://mastodon.social/@fmarini/116283365807945104

                              1 Reply Last reply
                              0
                              • gknauss@mastodon.socialG gknauss@mastodon.social

                                Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                                Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                                ppb1701@ppb.socialP This user is from outside of this forum
                                ppb1701@ppb.socialP This user is from outside of this forum
                                ppb1701@ppb.social
                                wrote last edited by
                                #17

                                @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                                gknauss@mastodon.socialG 1 Reply Last reply
                                0
                                • ppb1701@ppb.socialP ppb1701@ppb.social

                                  @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                                  gknauss@mastodon.socialG This user is from outside of this forum
                                  gknauss@mastodon.socialG This user is from outside of this forum
                                  gknauss@mastodon.social
                                  wrote last edited by
                                  #18

                                  @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                                  ppb1701@ppb.socialP 1 Reply Last reply
                                  0
                                  • gknauss@mastodon.socialG gknauss@mastodon.social

                                    @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                                    ppb1701@ppb.socialP This user is from outside of this forum
                                    ppb1701@ppb.socialP This user is from outside of this forum
                                    ppb1701@ppb.social
                                    wrote last edited by
                                    #19

                                    @gknauss nope that doesn't bode well. I do think they will eventually patch it...but it does seem more like they wanna say. "Sure it's patched, do the update to 26"

                                    1 Reply Last reply
                                    0
                                    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                                      @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                                      mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                      mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                      mirabilos@toot.mirbsd.org
                                      wrote last edited by
                                      #20

                                      @mttaggart @gknauss same for SE 2022 (funnily, my SE 2016 does get patched…)

                                      1 Reply Last reply
                                      0
                                      • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                                        @gknauss worse, it’ll patch it, just not for phones that can run 26

                                        mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                        mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                        mirabilos@toot.mirbsd.org
                                        wrote last edited by
                                        #21

                                        @jsnell @gknauss @mttaggart call customer support and file one at https://www.apple.com/feedback/iphone/

                                        if they get even 10 million requests, maybe they begin to think

                                        1 Reply Last reply
                                        0
                                        • gknauss@mastodon.socialG gknauss@mastodon.social

                                          @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                                          misty@digipres.clubM This user is from outside of this forum
                                          misty@digipres.clubM This user is from outside of this forum
                                          misty@digipres.club
                                          wrote last edited by
                                          #22

                                          @gknauss @mttaggart Try opting into the iOS 18 public beta from the software update settings. It should offer 18.7.3 as an update, and being on that beta branch will prevent iOS 26 from appearing as well.

                                          I did this when 18.7.3 came out since it wasn’t offered as “normal” update, just a final release on the beta branch. 18.7.4 on do seem to be exclusive to older devices though.

                                          1 Reply Last reply
                                          1
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups