So just so we're clear, my iPhone running last years iOS and I get to choose: Upgrade to Ugly Glass or risk exposing basically everything on the phone including passwords to any web site. Wow, that's really an impressive new low for Apple.

@peternlewis sloppy reporting, as usual.

Google has a more in depth analysis, with a lot more information on the specific versions of iOS that are affected.

TL;DR It doesn’t seem to affect 18.7.3 at least (might also not work on 18.7.2 given that CVE-2025-43520, which DarkSword uses, has been patched in .2).

https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

Google Cloud Blog

@fmarini OK, cool, but, where is 18.7.3? I'm running 18.7.1 and the only option shown to me in Software Update is 26.3.1.

I have automatically install Security Responses turned on and I have iOS updates "automatically download" also on.

According to Wikipedia, 18.7.6 was released *twenty days ago* 🤷‍♂️.

@tripleman you could try switching on iOS 18 public beta, it might (might, not sure) give you the option for 18.7.2 or 18.7.3. If it doesn’t, I guess you’re of luck, since from 18.7.4 on (or maybe even 18.7.3; I got it before they “forced” the 26 update for newer phones) it looks like they’re only for iPhone XR and XS 🤷🏼‍♂️

@fmarini Turned on 18 Beta updates and it says 18.7.1 iOS is up to date.

Soooooo, not so sloppy reporting.

@tripleman it is sloppy, because the ones on 18.7.2 and up aren’t affected, contrary to the “18 is affected” narrative.
@fmarini Well, only a small subset of phones can get further than 18.7.1 so, this is the reality for most users that want to stay on it.

@tripleman I’m on 18.7.3 on a 13 Pro. Every iPhone up to 16 received it, until Apple decided to make 18.7.3+ XR and XS only. So the ones that received either 18.7.2 or 18.7.3 and still haven’t upgraded to 26 are safe to stay on 18.7.x.

Saying that all 18.x are not safe is simply not true.