‹ Back to Home

Apple Just Pushed an Emergency iOS 18 Update — If You Haven't Upgraded to iOS 26, Install It Now

Apple rarely patches an older iOS version once a new one is out — but DarkSword is serious enough that they made an exception. If your iPhone is still on iOS 18 and you've been putting off that iOS 26 upgrade, there's now a critical security update you need to install immediately. Your messages, crypto wallet, and banking apps could be at risk.

Keerthika 6 min read 547
Follow on Google
Updated 5 months ago
iPhone Tips Apple Just Pushed an Emergency iOS 18 Update — If You Haven't Upgraded to iOS 26, Install It Now 6 min left Follow on Google
Apple Just Pushed an Emergency iOS 18 Update — If You Haven't Upgraded to iOS 26, Install It Now

TamilTech AI summary

Apple just broke its usual rule of stopping security updates for older iOS versions and pushed an emergency iOS 18.7.7 patch because a serious web-based exploit kit called DarkSword can quietly take over vulnerable iPhones just by visiting a compromised site—no shady app install or phishing tap required. DarkSword chains six vulnerabilities to install malware families like GhostBlade, GhostKnife, and GhostSaber, which can steal messages, passwords, photos, banking and crypto data, and keep remote access open without you noticing. The risk jumped hard after the exploit code landed publicly on GitHub, so everyday attackers—not only nation-state or commercial spyware groups—can now use it, and a large share of recent iPhones are still on iOS 18. If your iPhone is still running iOS 18 (from the XR through the 16 and 16e), go to Settings → General → Software Update and install 18.7.7 right away; Apple still prefers you move to iOS 26 when you can for the strongest protection, and Lockdown Mode already blocks these particular web attacks if you need extra hardening. This matters especially for anyone relying on WhatsApp, UPI apps, banking, or similar data on the device, so take the ten minutes and patch now rather than leave the door open.

  • Apple broke its own update policy to release iOS 18.7.7 — DarkSword exploit kit targets iPhones via web attacks, deploys 3 malware families stealing messages, crypto wallets, banking data
  • DarkSword code published on GitHub last month — now freely available to any attacker worldwide; 1 in 5 iPhones still on iOS 18 are vulnerable
  • Install now: Settings → General → Software Update → iOS 18.7.7; affects iPhone XR through iPhone 16 still on iOS 18; India's most popular iPhone models all in the list

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

Apple broke its own rules to push this update — that tells you everything

Apple has a clear policy: when a new major iOS version launches, older versions stop getting updates. If you want security fixes, you upgrade. That's been the rule for years, and Apple enforces it strictly.

So when Apple quietly released iOS 18.7.7 on April 1, 2026 — and specifically expanded it to iPhones that are fully capable of running iOS 26 — that's not routine. That's Apple saying: this threat is serious enough that we're making an exception.

The threat is called DarkSword, and if your iPhone is still running iOS 18, you need to update right now.

What is DarkSword and why is it unusually dangerous?

DarkSword is an exploit kit — think of it as a packaged toolkit that attackers can use to remotely compromise iPhones through web attacks. You don't need to install anything suspicious. You don't need to click a phishing link. Simply visiting a compromised website while running a vulnerable iOS version can be enough to get infected.

It exploits six separate security vulnerabilities in iOS — tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520. The combination of these vulnerabilities creates a full chain: attackers can get into the device, establish persistence, and exfiltrate data without the user ever noticing.

What makes DarkSword different from typical iOS exploits is scale. Most iPhone zero-days are used in narrow, highly targeted spyware campaigns against journalists, activists, or specific individuals — think Pegasus. DarkSword has been used much more broadly. A Turkish commercial surveillance vendor called PARS Defense has deployed it. A threat group tracked as UNC6748 has used it. A suspected Russian espionage operation tracked as UNC6353 has used it. This isn't boutique surveillance — it's been deployed as a wider-net attack tool.

The three malware families DarkSword installs

Once DarkSword successfully exploits an iPhone, it deploys one or more of three malware families that researchers have documented.

GhostBlade is a JavaScript-based infostealer — aggressively designed to pull data off the device as fast as possible. Messages, photos, saved passwords, app data. GhostKnife is a backdoor that gives the attacker persistent remote access to the device even after the initial exploit. GhostSaber is another JavaScript malware capable of executing code and stealing data from specific apps.

The combination is comprehensive. An attacker who fully deploys all three has essentially complete access to everything on the device — including banking apps, crypto wallets, WhatsApp message history, email, and anything stored locally.

The GitHub problem that forced Apple's hand

Here's the thing that escalated this from "serious" to "Apple breaks its own update policy": last month, a researcher published the DarkSword exploit kit code publicly on GitHub.

Before that, DarkSword was effectively limited to well-resourced threat actors — commercial surveillance vendors, nation-state espionage groups — who had the expertise to develop and deploy it themselves. The moment the code hit GitHub, any competent attacker anywhere in the world could download and adapt it. The barrier to using it dropped dramatically overnight.

Apple's own data shows roughly one-fifth of iPhones from the past four years are still running iOS 18. That's a massive pool of potentially vulnerable devices. Security researchers have called the public availability of the exploit kit "extremely worrisome" given that number — and described opportunistic mass attacks as now "very likely."

Apple's response: release iOS 18.7.7 and make it available to every iPhone going back to the XR, including the iPhone 16e and iPhone 16. Even devices that Apple had stopped offering iOS 18 updates to can now install this patch.

Which iPhones are getting the update?

The iOS 18.7.7 update is now available for: iPhone XR, iPhone XS and XS Max, iPhone 11 (all models), iPhone SE (2nd generation), iPhone 12 (all models), iPhone 13 (all models), iPhone SE (3rd generation), iPhone 14 (all models), iPhone 15 (all models), iPhone 16 (all models), and iPhone 16e.

Basically — if your iPhone can run iOS 26, it can now also get this critical iOS 18 security patch. This is specifically for users who have chosen to stay on iOS 18 and haven't upgraded yet.

Apple's official recommendation remains: update to iOS 26 if your device supports it, as it contains the strongest protections. But for those who haven't made that jump yet — iOS 18.7.7 is now available and critical.

Why India-based iPhone users should take this seriously

India has a very specific iPhone usage pattern that makes this particularly relevant. The iPhone XR, iPhone 11, iPhone 12, and iPhone SE models — all now getting this critical patch — are among the most popular iPhones in the Indian market. They hit the ₹30,000-55,000 sweet spot on Flipkart and Amazon India where iPhone purchases are most common, and millions of Indians are using these exact models right now.

The DarkSword attacks documented so far have been concentrated in Saudi Arabia, Turkey, Malaysia, and Ukraine. India isn't in that list — yet. But the moment the exploit code became publicly available on GitHub, geography stopped being a meaningful protection. Any attacker targeting India's large iPhone base can now use the same toolkit. Indian iPhone users who rely on GPay, PhonePe, banking apps, WhatsApp for business, and crypto trading apps are all carrying data that would be highly valuable to attackers.

There's also a practical reality in India: many users delay iOS upgrades because they've heard that new updates slow down older phones, or because they're happy with how their phone currently works. That hesitation is understandable — but right now it's creating genuine security risk.

How to install the update right now

Step 1: Open Settings on your iPhone.

Step 2: Tap General.

Step 3: Tap Software Update.

Step 4: If iOS 18.7.7 is available, you'll see the option to download and install it. Tap it and let it run.

If you have Automatic Updates enabled, your phone may already have downloaded the update in the background — check to see if it's waiting for you to install it.

If iOS 26 appears as an option instead of or alongside iOS 18.7.7, Apple's recommendation is to upgrade to iOS 26 for the strongest protection. But if you're not ready to make that jump, iOS 18.7.7 gives you the DarkSword protections without requiring the full OS upgrade.

One more thing: devices with Lockdown Mode enabled are already protected against these specific DarkSword web attacks, even without the patch. If you're a journalist, activist, or anyone in a high-risk profession, Lockdown Mode is worth knowing about — it's available in Settings → Privacy & Security → Lockdown Mode.

TamilTech's take

Apple breaking its standard update policy to patch iOS 18 is the clearest possible signal that DarkSword is not a routine security issue. When the company that normally forces you to upgrade to get security fixes instead comes to you with an emergency patch, you pay attention. If you're on iOS 18 and haven't updated yet — close this article, go to Settings, and install iOS 18.7.7 right now. It takes ten minutes. The alternative is leaving your WhatsApp history, banking apps, and everything else on your phone exposed to an exploit kit that's now freely downloadable by anyone on the planet.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,344 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story Siri Gets Smarter: One Query, Multiple Commands – And a Grammarly‑Like Keyboard for iOS
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications