Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Scheduled Pinned Locked Moved Uncategorized
22 Posts 13 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gknauss@mastodon.socialG gknauss@mastodon.social

    Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

    Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchange
    wrote last edited by
    #2

    @gknauss Hey! Do you have a source for this?

    gknauss@mastodon.socialG 1 Reply Last reply
    0
    • gknauss@mastodon.socialG gknauss@mastodon.social

      Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

      Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

      jsnell@zeppelin.flightsJ This user is from outside of this forum
      jsnell@zeppelin.flightsJ This user is from outside of this forum
      jsnell@zeppelin.flights
      wrote last edited by
      #3

      @gknauss worse, it’ll patch it, just not for phones that can run 26

      gknauss@mastodon.socialG abdalian@lingo.lolA mirabilos@toot.mirbsd.orgM 3 Replies Last reply
      0
      • gknauss@mastodon.socialG gknauss@mastodon.social

        Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

        Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

        abdalian@lingo.lolA This user is from outside of this forum
        abdalian@lingo.lolA This user is from outside of this forum
        abdalian@lingo.lol
        wrote last edited by
        #4

        @gknauss which are you choosing, Sophie?

        1 Reply Last reply
        0
        • gknauss@mastodon.socialG gknauss@mastodon.social

          Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

          Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

          cynblogger@sfba.socialC This user is from outside of this forum
          cynblogger@sfba.socialC This user is from outside of this forum
          cynblogger@sfba.social
          wrote last edited by
          #5

          @gknauss
          I’ve been one of the very reluctant upgradees to 26, but I bit the bullet last week on iPhone & iPad &…it’s all fine. I even like the (subdued) glass.

          1 Reply Last reply
          0
          • gknauss@mastodon.socialG gknauss@mastodon.social

            Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

            Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.townD This user is from outside of this forum
            drwho@masto.hackers.town
            wrote last edited by
            #6

            @gknauss Yes, they would.

            "This vulnerability is completely theoretical."

            1 Reply Last reply
            0
            • gknauss@mastodon.socialG gknauss@mastodon.social

              Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

              Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

              slyborg@vmst.ioS This user is from outside of this forum
              slyborg@vmst.ioS This user is from outside of this forum
              slyborg@vmst.io
              wrote last edited by
              #7

              @gknauss >letting malware hackers force your new UI that people hate on them

              It's a bold strategy Cotton, let's see if it pays off for 'em…

              1 Reply Last reply
              0
              • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                @gknauss worse, it’ll patch it, just not for phones that can run 26

                gknauss@mastodon.socialG This user is from outside of this forum
                gknauss@mastodon.socialG This user is from outside of this forum
                gknauss@mastodon.social
                wrote last edited by
                #8

                @jsnell If they hasn’t throttled the CPU because of the battery, I’d still be on my iPhone 6.

                AND NOBODY WOULD BE ON MY LAWN.

                1 Reply Last reply
                0
                • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                  @gknauss worse, it’ll patch it, just not for phones that can run 26

                  abdalian@lingo.lolA This user is from outside of this forum
                  abdalian@lingo.lolA This user is from outside of this forum
                  abdalian@lingo.lol
                  wrote last edited by
                  #9

                  @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

                  ultranurd@tacobelllabs.netU 1 Reply Last reply
                  0
                  • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                    @gknauss Hey! Do you have a source for this?

                    gknauss@mastodon.socialG This user is from outside of this forum
                    gknauss@mastodon.socialG This user is from outside of this forum
                    gknauss@mastodon.social
                    wrote last edited by
                    #10

                    @mttaggart Nothing explicit, but reading between the lines…

                    iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

                    Link Preview Image
                    Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

                    A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

                    favicon

                    WIRED (www.wired.com)

                    mttaggart@infosec.exchangeM 1 Reply Last reply
                    0
                    • gknauss@mastodon.socialG gknauss@mastodon.social

                      @mttaggart Nothing explicit, but reading between the lines…

                      iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

                      Link Preview Image
                      Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

                      A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

                      favicon

                      WIRED (www.wired.com)

                      mttaggart@infosec.exchangeM This user is from outside of this forum
                      mttaggart@infosec.exchangeM This user is from outside of this forum
                      mttaggart@infosec.exchange
                      wrote last edited by
                      #11

                      @gknauss I think the thing is to move to 18.7.3, which is patched.

                      For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

                      I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

                      Link Preview Image
                      The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

                      DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

                      favicon

                      Google Cloud Blog (cloud.google.com)

                      gknauss@mastodon.socialG 1 Reply Last reply
                      0
                      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                        @gknauss I think the thing is to move to 18.7.3, which is patched.

                        For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

                        I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

                        Link Preview Image
                        The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

                        DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

                        favicon

                        Google Cloud Blog (cloud.google.com)

                        gknauss@mastodon.socialG This user is from outside of this forum
                        gknauss@mastodon.socialG This user is from outside of this forum
                        gknauss@mastodon.social
                        wrote last edited by
                        #12

                        @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                        mttaggart@infosec.exchangeM misty@digipres.clubM 2 Replies Last reply
                        0
                        • gknauss@mastodon.socialG gknauss@mastodon.social

                          @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                          mttaggart@infosec.exchangeM This user is from outside of this forum
                          mttaggart@infosec.exchangeM This user is from outside of this forum
                          mttaggart@infosec.exchange
                          wrote last edited by
                          #13

                          @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                          mirabilos@toot.mirbsd.orgM 1 Reply Last reply
                          0
                          • abdalian@lingo.lolA abdalian@lingo.lol

                            @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

                            ultranurd@tacobelllabs.netU This user is from outside of this forum
                            ultranurd@tacobelllabs.netU This user is from outside of this forum
                            ultranurd@tacobelllabs.net
                            wrote last edited by
                            #14

                            @abdalian @jsnell @gknauss I'm kinda surprised more enterprise phone fleets (that haven't updated their apps for 26 yet) aren't screaming about this

                            1 Reply Last reply
                            0
                            • gknauss@mastodon.socialG gknauss@mastodon.social

                              Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                              Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                              K This user is from outside of this forum
                              K This user is from outside of this forum
                              ke7zum@glitchsoc.bg-presents.us
                              wrote last edited by
                              #15

                              @gknauss I have to agree. there was a patch that went very, very wrong in windows 11 this patch tuesday. Or was it last month? anyway MS just released a fix last week. Taht was indeed fast.

                              1 Reply Last reply
                              0
                              • gknauss@mastodon.socialG gknauss@mastodon.social

                                Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                                Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                                fmarini@mastodon.socialF This user is from outside of this forum
                                fmarini@mastodon.socialF This user is from outside of this forum
                                fmarini@mastodon.social
                                wrote last edited by
                                #16

                                @gknauss https://mastodon.social/@fmarini/116283365807945104

                                1 Reply Last reply
                                0
                                • gknauss@mastodon.socialG gknauss@mastodon.social

                                  Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                                  Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                                  ppb1701@ppb.socialP This user is from outside of this forum
                                  ppb1701@ppb.socialP This user is from outside of this forum
                                  ppb1701@ppb.social
                                  wrote last edited by
                                  #17

                                  @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                                  gknauss@mastodon.socialG 1 Reply Last reply
                                  0
                                  • ppb1701@ppb.socialP ppb1701@ppb.social

                                    @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                                    gknauss@mastodon.socialG This user is from outside of this forum
                                    gknauss@mastodon.socialG This user is from outside of this forum
                                    gknauss@mastodon.social
                                    wrote last edited by
                                    #18

                                    @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                                    ppb1701@ppb.socialP 1 Reply Last reply
                                    0
                                    • gknauss@mastodon.socialG gknauss@mastodon.social

                                      @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                                      ppb1701@ppb.socialP This user is from outside of this forum
                                      ppb1701@ppb.socialP This user is from outside of this forum
                                      ppb1701@ppb.social
                                      wrote last edited by
                                      #19

                                      @gknauss nope that doesn't bode well. I do think they will eventually patch it...but it does seem more like they wanna say. "Sure it's patched, do the update to 26"

                                      1 Reply Last reply
                                      0
                                      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                                        @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                                        mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                        mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                        mirabilos@toot.mirbsd.org
                                        wrote last edited by
                                        #20

                                        @mttaggart @gknauss same for SE 2022 (funnily, my SE 2016 does get patched…)

                                        1 Reply Last reply
                                        0
                                        • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                                          @gknauss worse, it’ll patch it, just not for phones that can run 26

                                          mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                          mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                          mirabilos@toot.mirbsd.org
                                          wrote last edited by
                                          #21

                                          @jsnell @gknauss @mttaggart call customer support and file one at https://www.apple.com/feedback/iphone/

                                          if they get even 10 million requests, maybe they begin to think

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups