Apple has pushed out a targeted security fix for users still running iOS 18 and iPadOS 18, closing critical vulnerabilities exploited by the DarkSword attack kit.
The company released iOS 18.7.7 and iPadOS 18.7.7 on Wednesday, backporting protections that were previously available only on newer iOS 26 versions. The update addresses a chain of flaws in WebKit, JavaScriptCore, and dyld that could allow remote code execution through malicious websites or phishing links.
DarkSword is a sophisticated exploit framework capable of silently compromising devices to steal credentials, photos, emails, and cryptocurrency wallet data. Security researchers first exposed the kit in March, warning that it was already being used by multiple threat actors, including suspected state-sponsored groups. Its partial leak online has heightened fears of wider adoption by lower-skilled attackers.
By extending the patch to older hardware still on iOS 18, Apple is giving millions of holdout users a chance to protect themselves without forcing an immediate jump to the latest major OS. Devices with automatic updates enabled should receive the fix automatically; others can install it manually through Settings > General > Software Update.
The move reflects Apple’s ongoing effort to maintain security across its long-tail installed base, where many users delay major upgrades due to performance concerns on older iPhones and iPads. Apple continues to recommend enabling Lockdown Mode for high-risk individuals and urges everyone to keep their devices updated.
For users still on iOS 18, the advice is simple: install iOS 18.7.7 as soon as possible to shut the door on DarkSword before attacks become more widespread.





