Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

Scheduled Pinned Locked Moved Uncategorized
22 Posts 13 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gknauss@mastodon.socialG This user is from outside of this forum
    gknauss@mastodon.socialG This user is from outside of this forum
    gknauss@mastodon.social
    wrote last edited by
    #1

    Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

    Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

    mttaggart@infosec.exchangeM jsnell@zeppelin.flightsJ abdalian@lingo.lolA cynblogger@sfba.socialC drwho@masto.hackers.townD 9 Replies Last reply
    2
    0
    • R relay@relay.infosec.exchange shared this topic
      mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
    • gknauss@mastodon.socialG gknauss@mastodon.social

      Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

      Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

      mttaggart@infosec.exchangeM This user is from outside of this forum
      mttaggart@infosec.exchangeM This user is from outside of this forum
      mttaggart@infosec.exchange
      wrote last edited by
      #2

      @gknauss Hey! Do you have a source for this?

      gknauss@mastodon.socialG 1 Reply Last reply
      0
      • gknauss@mastodon.socialG gknauss@mastodon.social

        Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

        Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

        jsnell@zeppelin.flightsJ This user is from outside of this forum
        jsnell@zeppelin.flightsJ This user is from outside of this forum
        jsnell@zeppelin.flights
        wrote last edited by
        #3

        @gknauss worse, it’ll patch it, just not for phones that can run 26

        gknauss@mastodon.socialG abdalian@lingo.lolA mirabilos@toot.mirbsd.orgM 3 Replies Last reply
        0
        • gknauss@mastodon.socialG gknauss@mastodon.social

          Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

          Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

          abdalian@lingo.lolA This user is from outside of this forum
          abdalian@lingo.lolA This user is from outside of this forum
          abdalian@lingo.lol
          wrote last edited by
          #4

          @gknauss which are you choosing, Sophie?

          1 Reply Last reply
          0
          • gknauss@mastodon.socialG gknauss@mastodon.social

            Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

            Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

            cynblogger@sfba.socialC This user is from outside of this forum
            cynblogger@sfba.socialC This user is from outside of this forum
            cynblogger@sfba.social
            wrote last edited by
            #5

            @gknauss
            I’ve been one of the very reluctant upgradees to 26, but I bit the bullet last week on iPhone & iPad &…it’s all fine. I even like the (subdued) glass.

            1 Reply Last reply
            0
            • gknauss@mastodon.socialG gknauss@mastodon.social

              Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

              Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.townD This user is from outside of this forum
              drwho@masto.hackers.town
              wrote last edited by
              #6

              @gknauss Yes, they would.

              "This vulnerability is completely theoretical."

              1 Reply Last reply
              0
              • gknauss@mastodon.socialG gknauss@mastodon.social

                Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                slyborg@vmst.ioS This user is from outside of this forum
                slyborg@vmst.ioS This user is from outside of this forum
                slyborg@vmst.io
                wrote last edited by
                #7

                @gknauss >letting malware hackers force your new UI that people hate on them

                It's a bold strategy Cotton, let's see if it pays off for 'em…

                1 Reply Last reply
                0
                • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                  @gknauss worse, it’ll patch it, just not for phones that can run 26

                  gknauss@mastodon.socialG This user is from outside of this forum
                  gknauss@mastodon.socialG This user is from outside of this forum
                  gknauss@mastodon.social
                  wrote last edited by
                  #8

                  @jsnell If they hasn’t throttled the CPU because of the battery, I’d still be on my iPhone 6.

                  AND NOBODY WOULD BE ON MY LAWN.

                  1 Reply Last reply
                  0
                  • jsnell@zeppelin.flightsJ jsnell@zeppelin.flights

                    @gknauss worse, it’ll patch it, just not for phones that can run 26

                    abdalian@lingo.lolA This user is from outside of this forum
                    abdalian@lingo.lolA This user is from outside of this forum
                    abdalian@lingo.lol
                    wrote last edited by
                    #9

                    @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

                    ultranurd@tacobelllabs.netU 1 Reply Last reply
                    0
                    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                      @gknauss Hey! Do you have a source for this?

                      gknauss@mastodon.socialG This user is from outside of this forum
                      gknauss@mastodon.socialG This user is from outside of this forum
                      gknauss@mastodon.social
                      wrote last edited by
                      #10

                      @mttaggart Nothing explicit, but reading between the lines…

                      iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

                      Link Preview Image
                      Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

                      A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

                      favicon

                      WIRED (www.wired.com)

                      mttaggart@infosec.exchangeM 1 Reply Last reply
                      0
                      • gknauss@mastodon.socialG gknauss@mastodon.social

                        @mttaggart Nothing explicit, but reading between the lines…

                        iOS 26 has been fixed. iOS 18 for devices that can’t run iOS 26 has been fixed. And those who can run iOS 26 but don’t want to? [Conspicuous silence.]

                        Link Preview Image
                        Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

                        A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. It can take over devices running iOS 18 that simply visit infected websites.

                        favicon

                        WIRED (www.wired.com)

                        mttaggart@infosec.exchangeM This user is from outside of this forum
                        mttaggart@infosec.exchangeM This user is from outside of this forum
                        mttaggart@infosec.exchange
                        wrote last edited by
                        #11

                        @gknauss I think the thing is to move to 18.7.3, which is patched.

                        For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

                        I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

                        Link Preview Image
                        The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

                        DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

                        favicon

                        Google Cloud Blog (cloud.google.com)

                        gknauss@mastodon.socialG 1 Reply Last reply
                        0
                        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                          @gknauss I think the thing is to move to 18.7.3, which is patched.

                          For devices running versions of iOS prior to 18.6, DarkSword uses CVE-2025-31277, a JIT optimization/type confusion bug which was patched by Apple in iOS 18.6. For devices running iOS 18.6-18.7, DarkSword uses CVE-2025-43529, a garbage collection bug in the Data Flow Graph (DFG) JIT layer of JavaScriptCore which was patched by Apple in iOS 18.7.3 and 26.2 after it was reported by GTIG. Both exploits develop their own fakeobj/addrof primitives, and then build arbitrary read/write primitives the same way on top of them.

                          I'm unaware of a compelling reason or hardware limitation to not upgrade from 18.6 to 18.7

                          Link Preview Image
                          The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

                          DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

                          favicon

                          Google Cloud Blog (cloud.google.com)

                          gknauss@mastodon.socialG This user is from outside of this forum
                          gknauss@mastodon.socialG This user is from outside of this forum
                          gknauss@mastodon.social
                          wrote last edited by
                          #12

                          @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                          mttaggart@infosec.exchangeM misty@digipres.clubM 2 Replies Last reply
                          0
                          • gknauss@mastodon.socialG gknauss@mastodon.social

                            @mttaggart 18.7.X isn’t offered to me, since I’m on a iPhone 15 Pro. It’s either up to 26 or staying at 18.6.2.

                            mttaggart@infosec.exchangeM This user is from outside of this forum
                            mttaggart@infosec.exchangeM This user is from outside of this forum
                            mttaggart@infosec.exchange
                            wrote last edited by
                            #13

                            @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                            mirabilos@toot.mirbsd.orgM 1 Reply Last reply
                            0
                            • abdalian@lingo.lolA abdalian@lingo.lol

                              @jsnell @gknauss I was hoping that the iOS 18 developer betas would continue to push patches. It's unconscionable not to. I truly do not understand it other than trying to push their iOS 26 adoption numbers.

                              ultranurd@tacobelllabs.netU This user is from outside of this forum
                              ultranurd@tacobelllabs.netU This user is from outside of this forum
                              ultranurd@tacobelllabs.net
                              wrote last edited by
                              #14

                              @abdalian @jsnell @gknauss I'm kinda surprised more enterprise phone fleets (that haven't updated their apps for 26 yet) aren't screaming about this

                              1 Reply Last reply
                              0
                              • gknauss@mastodon.socialG gknauss@mastodon.social

                                Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                                Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                                K This user is from outside of this forum
                                K This user is from outside of this forum
                                ke7zum@glitchsoc.bg-presents.us
                                wrote last edited by
                                #15

                                @gknauss I have to agree. there was a patch that went very, very wrong in windows 11 this patch tuesday. Or was it last month? anyway MS just released a fix last week. Taht was indeed fast.

                                1 Reply Last reply
                                0
                                • gknauss@mastodon.socialG gknauss@mastodon.social

                                  Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                                  Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                                  fmarini@mastodon.socialF This user is from outside of this forum
                                  fmarini@mastodon.socialF This user is from outside of this forum
                                  fmarini@mastodon.social
                                  wrote last edited by
                                  #16

                                  @gknauss https://mastodon.social/@fmarini/116283365807945104

                                  1 Reply Last reply
                                  0
                                  • gknauss@mastodon.socialG gknauss@mastodon.social

                                    Apparently, Apple isn’t going to patch iOS 18.6.2, meaning I either risk my information with DarkSword or my sanity with iOS 26.

                                    Say what you want about Microsoft — please! use profanity! — but they wouldn’t let a zero-interaction, full-exfil bug go unfixed on a seven month old release.

                                    ppb1701@ppb.socialP This user is from outside of this forum
                                    ppb1701@ppb.socialP This user is from outside of this forum
                                    ppb1701@ppb.social
                                    wrote last edited by
                                    #17

                                    @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                                    gknauss@mastodon.socialG 1 Reply Last reply
                                    0
                                    • ppb1701@ppb.socialP ppb1701@ppb.social

                                      @gknauss they still might drop one, but apparently priority was 26.4 getting out the door. if they do it's might be like in between 26.5b2 and 3 or something weird like that

                                      gknauss@mastodon.socialG This user is from outside of this forum
                                      gknauss@mastodon.socialG This user is from outside of this forum
                                      gknauss@mastodon.social
                                      wrote last edited by
                                      #18

                                      @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                                      ppb1701@ppb.socialP 1 Reply Last reply
                                      0
                                      • gknauss@mastodon.socialG gknauss@mastodon.social

                                        @ppb1701 That they’ve already released 18.7.3 for phones that can’t upgrade to 26 but nothing for those that can does not bode well, alas. “Upgrade to 26” is the current recommendation, which just happens to suit their interests (and not mine).

                                        ppb1701@ppb.socialP This user is from outside of this forum
                                        ppb1701@ppb.socialP This user is from outside of this forum
                                        ppb1701@ppb.social
                                        wrote last edited by
                                        #19

                                        @gknauss nope that doesn't bode well. I do think they will eventually patch it...but it does seem more like they wanna say. "Sure it's patched, do the update to 26"

                                        1 Reply Last reply
                                        0
                                        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                                          @gknauss Ah I see, and you'd rather not run into the Liquid Glass ceiling. That does seem to be an issue!

                                          mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                          mirabilos@toot.mirbsd.orgM This user is from outside of this forum
                                          mirabilos@toot.mirbsd.org
                                          wrote last edited by
                                          #20

                                          @mttaggart @gknauss same for SE 2022 (funnily, my SE 2016 does get patched…)

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups