Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Scheduled Pinned Locked Moved Uncategorized
22 Posts 13 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gknauss@mastodon.socialG gknauss@mastodon.social

    @mttaggart Nothing explicit, but reading between the lines…

    iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

    Link Preview Image
    Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

    A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

    favicon

    WIRED (www.wired.com)

    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchange
    wrote last edited by
    #11

    @gknauss I think the thing is to move to 18.7.3, which is patched.

    For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

    I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

    Link Preview Image
    The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

    DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

    favicon

    Google Cloud Blog (cloud.google.com)

    gknauss@mastodon.socialG 1 Reply Last reply
    0
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

      @gknauss I think the thing is to move to 18.7.3, which is patched.

      For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

      I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

      Link Preview Image
      The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

      DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

      favicon

      Google Cloud Blog (cloud.google.com)

      gknauss@mastodon.socialG This user is from outside of this forum
      gknauss@mastodon.socialG This user is from outside of this forum
      gknauss@mastodon.social
      wrote last edited by
      #12

      @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

      mttaggart@infosec.exchangeM misty@digipres.clubM 2 Replies Last reply
      0
      • gknauss@mastodon.socialG gknauss@mastodon.social

        @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

        mttaggart@infosec.exchangeM This user is from outside of this forum
        mttaggart@infosec.exchangeM This user is from outside of this forum
        mttaggart@infosec.exchange
        wrote last edited by
        #13

        @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

        mirabilos@toot.mirbsd.orgM 1 Reply Last reply
        0
        • abdalian@lingo.lolA abdalian@lingo.lol

          @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

          ultranurd@tacobelllabs.netU This user is from outside of this forum
          ultranurd@tacobelllabs.netU This user is from outside of this forum
          ultranurd@tacobelllabs.net
          wrote last edited by
          #14

          @abdalian @jsnell @gknauss I'm kinda surprised more enterprise phone fleets (that haven't updated their apps for 26 yet) aren't screaming about this

          1 Reply Last reply
          0
          • gknauss@mastodon.socialG gknauss@mastodon.social

            Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

            Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

            K This user is from outside of this forum
            K This user is from outside of this forum
            ke7zum@glitchsoc.bg-presents.us
            wrote last edited by
            #15

            @gknauss I have to agree. there was a patch that went very, very wrong in windows 11 this patch tuesday. Or was it last month? anyway MS just released a fix last week. Taht was indeed fast.

            1 Reply Last reply
            0
            • gknauss@mastodon.socialG gknauss@mastodon.social

              Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

              Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

              fmarini@mastodon.socialF This user is from outside of this forum
              fmarini@mastodon.socialF This user is from outside of this forum
              fmarini@mastodon.social
              wrote last edited by
              #16

              @gknauss https://mastodon.social/@fmarini/116283365807945104

              1 Reply Last reply
              0
              • gknauss@mastodon.socialG gknauss@mastodon.social

                Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                ppb1701@ppb.socialP This user is from outside of this forum
                ppb1701@ppb.socialP This user is from outside of this forum
                ppb1701@ppb.social
                wrote last edited by
                #17

                @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                gknauss@mastodon.socialG 1 Reply Last reply
                0
                • ppb1701@ppb.socialP ppb1701@ppb.social

                  @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                  gknauss@mastodon.socialG This user is from outside of this forum
                  gknauss@mastodon.socialG This user is from outside of this forum
                  gknauss@mastodon.social
                  wrote last edited by
                  #18

                  @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                  ppb1701@ppb.socialP 1 Reply Last reply
                  0
                  • gknauss@mastodon.socialG gknauss@mastodon.social

                    @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                    ppb1701@ppb.socialP This user is from outside of this forum
                    ppb1701@ppb.socialP This user is from outside of this forum
                    ppb1701@ppb.social
                    wrote last edited by
                    #19

                    @gknauss nope that doesn't bode well. I do think they will eventually patch it...but it does seem more like they wanna say. "Sure it's patched, do the update to 26"

                    1 Reply Last reply
                    0
                    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                      @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                      mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                      mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                      mirabilos@toot.mirbsd.org
                      wrote last edited by
                      #20

                      @mttaggart @gknauss same for SE 2022 (funnily, my SE 2016 does get patched…)

                      1 Reply Last reply
                      0
                      • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                        @gknauss worse, it’ll patch it, just not for phones that can run 26

                        mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                        mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                        mirabilos@toot.mirbsd.org
                        wrote last edited by
                        #21

                        @jsnell @gknauss @mttaggart call customer support and file one at https://www.apple.com/feedback/iphone/

                        if they get even 10 million requests, maybe they begin to think

                        1 Reply Last reply
                        0
                        • gknauss@mastodon.socialG gknauss@mastodon.social

                          @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                          misty@digipres.clubM This user is from outside of this forum
                          misty@digipres.clubM This user is from outside of this forum
                          misty@digipres.club
                          wrote last edited by
                          #22

                          @gknauss @mttaggart Try opting into the iOS 18 public beta from the software update settings. It should offer 18.7.3 as an update, and being on that beta branch will prevent iOS 26 from appearing as well.

                          I did this when 18.7.3 came out since it wasn’t offered as “normal” update, just a final release on the beta branch. 18.7.4 on do seem to be exclusive to older devices though.

                          1 Reply Last reply
                          1
                          0
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • World
                          • Users
                          • Groups