Google’s Threat Intelligence Group (GTIG) has detailed a sophisticated iOS exploit chain dubbed DarkSword, used by multiple commercial surveillance vendors and suspected state-sponsored actors to fully compromise iPhones via Safari and steal sensitive data, including contents of cryptocurrency wallets. The attack begins when a target visits a malicious or compromised website in Safari, triggering a sequence of zero‑day exploits that achieve remote code execution, escape the browser sandbox, escalate to kernel privileges, and deploy in‑memory spyware implants.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Google

Comments