Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

PSA: Hackers can raid iOS 18 with an infected link | The Verge

Security researchers have discovered a vulnerability impacting iOS 18.4 to 18.6.2, which can allow hackers to steal text messages, credentials, cryptocurrenc...

TechnologyInnovationBest PracticesGuideTutorial
PSA: Hackers can raid iOS 18 with an infected link | The Verge
Listen to Article
0:00
0:00
0:00

PSA: Hackers can raid i OS 18 with an infected link | The Verge

Overview

Tech Expand Amazon Apple Facebook Google Microsoft Samsung Business See all tech

Reviews Expand Smart Home Reviews Phone Reviews Tablet Reviews Headphone Reviews See all reviews

Details

Science Expand Space Energy Environment Health See all science

Entertainment Expand TV Shows Movies Audio See all entertainment

Policy Expand Antitrust Politics Law Security See all policy

Gadgets Expand Laptops Phones TVs Headphones Speakers Wearables See all gadgets

Verge Shopping Expand Buying Guides Deals Gift Guides See all shopping

Streaming Expand Disney HBONetflix You Tube Creators See all streaming

Transportation Expand Electric Cars Autonomous Cars Ride-sharing Scooters See all transportation

Tech Close Tech Posts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All Tech

Posts from this topic will be added to your daily email digest and your homepage feed.

Apple Close Apple Posts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All Apple

Posts from this topic will be added to your daily email digest and your homepage feed.

Security Close Security Posts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All Security

Posts from this topic will be added to your daily email digest and your homepage feed.

PSA: Hackers can raid i OS 18 with an infected link

The ‘Dark Sword’ attack technique can covertly steal messages, contacts, saved credentials, cryptocurrency wallets, and more on i Phones running i OS 18.4 to 18.6.2.

The ‘Dark Sword’ attack technique can covertly steal messages, contacts, saved credentials, cryptocurrency wallets, and more on i Phones running i OS 18.4 to 18.6.2.

Posts from this author will be added to your daily email digest and your homepage feed.

If you buy something from a Verge link, Vox Media may earn a commission. See our ethics statement.

Posts from this author will be added to your daily email digest and your homepage feed.

If you’ve been putting off an update to i OS 26, now might be the time to do it. On Wednesday, security researchers published findings on a new hacking tool that targets i Phones running i OS 18.4 to 18.6.2, as reported earlier by Wired. The “Dark Sword” exploit allows bad actors to scoop up the personal information on i Phones that visit malicious links, and has already been used by Russian hackers.

The Google Threat Intelligence Group worked with the cybersecurity firms Lookout and i Verify to analyze the attack, which could affect up to 270 million devices still running the impacted versions of i OS 18. When a user accesses a compromised website, Google says Dark Sword uses “six different vulnerabilities” to carry out an attack targeting Safari, giving bad actors the ability to collect text messages, contacts, saved credentials, i Cloud files, photos, cryptocurrency wallets, call logs, location history, and more.

Google says it reported the vulnerability to Apple in late 2025. In an emailed statement to The Verge, Apple spokesperson Sarah O’Rourke confirmed that Apple had patched all “underlying vulnerabilities” in i OS last year before issuing an “emergency software update last week for older devices that were unable to update to more recent versions of i OS.”

Dark Sword uses a “hit-and-run” design that allows attackers to “extract high-value data and disappear before traditional detection methods can respond,” according to Lookout. Google says suspected Russian state-sponsored hackers used Dark Sword to target users in Ukraine, Saudi Arabia, Malaysia, and Turkey. These hackers were also discovered using an i OS exploit kit called Coruna, which Google highlighted in a report earlier this month. i Verify notes that the Russia-linked hackers left the Dark Sword code “unobfuscated, unprotected and easily accessible,” making it easy for other bad actors to access and potentially redeploy.

Google, Lookout, and i Verify found that the attack doesn’t impact users in Lockdown Mode, an “extreme” security feature for the i Phone that protects journalists, activists, and politicians from targeted attacks. Apple and Google have also blocked the malicious links used in Dark Sword attacks in Safari and Chrome.

“Keeping software up to date remains the single most important thing users can do to maintain the high security of their Apple devices as these updates include the latest security fixes and protections,” O’Rourke says.

Emma Roth Close Emma Roth News Writer Posts from this author will be added to your daily email digest and your homepage feed. Follow Follow See All by Emma Roth

Posts from this author will be added to your daily email digest and your homepage feed.

Apple Close Apple Posts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All Apple

Posts from this topic will be added to your daily email digest and your homepage feed.

i OSClosei OSPosts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All i OS

Posts from this topic will be added to your daily email digest and your homepage feed.

Security Close Security Posts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All Security

Posts from this topic will be added to your daily email digest and your homepage feed.

Tech Close Tech Posts from this topic will be added to your daily email digest and your homepage feed. Follow Follow See All Tech

Posts from this topic will be added to your daily email digest and your homepage feed.

Samsung discontinues its Galaxy Z Tri Fold after just three months

Spotify adds ‘Exclusive Mode’ audiophile feature for Windows PCs

Ikea tried to build a smart home for everyone — here’s why it’s not working yet

Benjamin Netanyahu is struggling to prove he’s not an AI clone

Key Takeaways

  • Tech Expand Amazon Apple Facebook Google Microsoft Samsung Business See all tech
  • Reviews Expand Smart Home Reviews Phone Reviews Tablet Reviews Headphone Reviews See all reviews
  • Science Expand Space Energy Environment Health See all science
  • Entertainment Expand TV Shows Movies Audio See all entertainment
  • Policy Expand Antitrust Politics Law Security See all policy

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.