Apple Expands iOS 18.7.7 Availability to Combat DarkSword Exploit Kit
**Apple** has broadened the availability of **iOS 18.7.7**, bringing crucial security updates to a wider range of devices still running the older operating system. This update specifically targets vulnerabilities exploited by the **DarkSword** exploit kit, which has been used in information-stealing attacks.

**Apple** is now providing security updates to more iPhones running **iOS 18**, safeguarding them against the actively exploited **DarkSword** exploit kit.
"We enabled the availability of iOS 18.7.7 for more devices on April 1, 2026, so users with Automatic Updates turned on can automatically receive important security protections from web attacks called DarkSword," states the **iOS 18.7.7** security update changelog.
"The fixes associated with the DarkSword exploit first shipped in 2025."
## DarkSword Exploit Kit
In March, researchers at **Lookout**, **iVerify**, and **Google Threat Intelligence** revealed a new **"DarkSword"** exploit kit targeting iPhones running **iOS 18.4** through **18.7**. This exploit kit leverages six vulnerabilities, tracked as **CVE-2025-31277**, **CVE-2025-43529**, **CVE-2026-20700**, **CVE-2025-14174**, **CVE-2025-43510**, and **CVE-2025-43520**.
Unlike typical iOS exploits used in targeted spyware campaigns, **DarkSword** has seen broader use, including by the Turkish commercial surveillance vendor **PARS Defense**, threat actor **UNC6748**, and a suspected Russian espionage group **UNC6353**.
These attacks involved the deployment of three distinct information-stealing malware families: the aggressive JavaScript infostealer **GhostBlade**, the **GhostKnife** backdoor, and the **GhostSaber** JavaScript malware capable of code execution and data theft.
## Patching Efforts and Limited Availability
Since **iOS 18.6** in July 2025, **Apple** has been addressing these vulnerabilities through security updates. However, by late 2025, **iOS 18** updates were discontinued for newer devices compatible with **iOS 26**, limiting security updates for those remaining on **iOS 18**.
Only a small subset of devices continued to receive **iOS 18** updates, with the last **18.7.6** update limited to **iPhone XS**, **iPhone XS Max**, and **iPhone XR** devices.
Further complicating matters, the **DarkSword** exploit kit was publicly leaked on **GitHub** last month, increasing the risk to older iPhones.

## Expanded Availability of iOS 18.7.7
**Apple** has now released **iOS 18.7.7** to provide continued protection against the latest threats for devices remaining on the older operating system.
Eligible devices now include: **iPhone XR**, **iPhone XS**, **iPhone XS Max**, **iPhone 11** (all models), **iPhone SE** (2nd generation), **iPhone 12** (all models), **iPhone 13** (all models), **iPhone SE** (3rd generation), **iPhone 14** (all models), **iPhone 15** (all models), **iPhone 16** (all models), **iPhone 16e**, **iPad mini** (5th generation - A17 Pro), **iPad** (7th generation - A16), **iPad Air** (3rd - 5th generation), **iPad Air 11-inch** (M2 - M3), **iPad Air 13-inch** (M2 - M3), **iPad Pro 11-inch** (1st generation - M4), **iPad Pro 12.9-inch** (3rd - 6th generation), and **iPad Pro 13-inch** (M4).
iPhone users still running **iOS 18** with Automatic Updates enabled will now receive the latest version and protections against the **DarkSword** exploit kit.