Apple broke its own rules to push this update — that tells you everything
Apple has a clear policy: when a new major iOS version launches, older versions stop getting updates. If you want security fixes, you upgrade. That's been the rule for years, and Apple enforces it strictly.
So when Apple quietly released iOS 18.7.7 on April 1, 2026 — and specifically expanded it to iPhones that are fully capable of running iOS 26 — that's not routine. That's Apple saying: this threat is serious enough that we're making an exception.
The threat is called DarkSword, and if your iPhone is still running iOS 18, you need to update right now.
What is DarkSword and why is it unusually dangerous?
DarkSword is an exploit kit — think of it as a packaged toolkit that attackers can use to remotely compromise iPhones through web attacks. You don't need to install anything suspicious. You don't need to click a phishing link. Simply visiting a compromised website while running a vulnerable iOS version can be enough to get infected.
It exploits six separate security vulnerabilities in iOS — tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520. The combination of these vulnerabilities creates a full chain: attackers can get into the device, establish persistence, and exfiltrate data without the user ever noticing.
What makes DarkSword different from typical iOS exploits is scale. Most iPhone zero-days are used in narrow, highly targeted spyware campaigns against journalists, activists, or specific individuals — think Pegasus. DarkSword has been used much more broadly. A Turkish commercial surveillance vendor called PARS Defense has deployed it. A threat group tracked as UNC6748 has used it. A suspected Russian espionage operation tracked as UNC6353 has used it. This isn't boutique surveillance — it's been deployed as a wider-net attack tool.
The three malware families DarkSword installs
Once DarkSword successfully exploits an iPhone, it deploys one or more of three malware families that researchers have documented.
GhostBlade is a JavaScript-based infostealer — aggressively designed to pull data off the device as fast as possible. Messages, photos, saved passwords, app data. GhostKnife is a backdoor that gives the attacker persistent remote access to the device even after the initial exploit. GhostSaber is another JavaScript malware capable of executing code and stealing data from specific apps.
The combination is comprehensive. An attacker who fully deploys all three has essentially complete access to everything on the device — including banking apps, crypto wallets, WhatsApp message history, email, and anything stored locally.
The GitHub problem that forced Apple's hand
Here's the thing that escalated this from "serious" to "Apple breaks its own update policy": last month, a researcher published the DarkSword exploit kit code publicly on GitHub.
Before that, DarkSword was effectively limited to well-resourced threat actors — commercial surveillance vendors, nation-state espionage groups — who had the expertise to develop and deploy it themselves. The moment the code hit GitHub, any competent attacker anywhere in the world could download and adapt it. The barrier to using it dropped dramatically overnight.
Apple's own data shows roughly one-fifth of iPhones from the past four years are still running iOS 18. That's a massive pool of potentially vulnerable devices. Security researchers have called the public availability of the exploit kit "extremely worrisome" given that number — and described opportunistic mass attacks as now "very likely."
Apple's response: release iOS 18.7.7 and make it available to every iPhone going back to the XR, including the iPhone 16e and iPhone 16. Even devices that Apple had stopped offering iOS 18 updates to can now install this patch.
Which iPhones are getting the update?
The iOS 18.7.7 update is now available for: iPhone XR, iPhone XS and XS Max, iPhone 11 (all models), iPhone SE (2nd generation), iPhone 12 (all models), iPhone 13 (all models), iPhone SE (3rd generation), iPhone 14 (all models), iPhone 15 (all models), iPhone 16 (all models), and iPhone 16e.
Basically — if your iPhone can run iOS 26, it can now also get this critical iOS 18 security patch. This is specifically for users who have chosen to stay on iOS 18 and haven't upgraded yet.
Apple's official recommendation remains: update to iOS 26 if your device supports it, as it contains the strongest protections. But for those who haven't made that jump yet — iOS 18.7.7 is now available and critical.
Why India-based iPhone users should take this seriously
India has a very specific iPhone usage pattern that makes this particularly relevant. The iPhone XR, iPhone 11, iPhone 12, and iPhone SE models — all now getting this critical patch — are among the most popular iPhones in the Indian market. They hit the ₹30,000-55,000 sweet spot on Flipkart and Amazon India where iPhone purchases are most common, and millions of Indians are using these exact models right now.
The DarkSword attacks documented so far have been concentrated in Saudi Arabia, Turkey, Malaysia, and Ukraine. India isn't in that list — yet. But the moment the exploit code became publicly available on GitHub, geography stopped being a meaningful protection. Any attacker targeting India's large iPhone base can now use the same toolkit. Indian iPhone users who rely on GPay, PhonePe, banking apps, WhatsApp for business, and crypto trading apps are all carrying data that would be highly valuable to attackers.
There's also a practical reality in India: many users delay iOS upgrades because they've heard that new updates slow down older phones, or because they're happy with how their phone currently works. That hesitation is understandable — but right now it's creating genuine security risk.
How to install the update right now
Step 1: Open Settings on your iPhone.
Step 2: Tap General.
Step 3: Tap Software Update.
Step 4: If iOS 18.7.7 is available, you'll see the option to download and install it. Tap it and let it run.
If you have Automatic Updates enabled, your phone may already have downloaded the update in the background — check to see if it's waiting for you to install it.
If iOS 26 appears as an option instead of or alongside iOS 18.7.7, Apple's recommendation is to upgrade to iOS 26 for the strongest protection. But if you're not ready to make that jump, iOS 18.7.7 gives you the DarkSword protections without requiring the full OS upgrade.
One more thing: devices with Lockdown Mode enabled are already protected against these specific DarkSword web attacks, even without the patch. If you're a journalist, activist, or anyone in a high-risk profession, Lockdown Mode is worth knowing about — it's available in Settings → Privacy & Security → Lockdown Mode.
TamilTech's take
Apple breaking its standard update policy to patch iOS 18 is the clearest possible signal that DarkSword is not a routine security issue. When the company that normally forces you to upgrade to get security fixes instead comes to you with an emergency patch, you pay attention. If you're on iOS 18 and haven't updated yet — close this article, go to Settings, and install iOS 18.7.7 right now. It takes ten minutes. The alternative is leaving your WhatsApp history, banking apps, and everything else on your phone exposed to an exploit kit that's now freely downloadable by anyone on the planet.




Comments (0)
Be the first to comment!