CVE-2025-31277Tuesday, March 24, 2026

Apple DarkSword: WebKit Buffer Overflow Exploited in iOS Spy Campaign

A buffer overflow vulnerability exists in Apple's WebKit rendering engine (CWE-119). Processing maliciously crafted web content may lead to memory corruption. This vulnerability is one of six zero-days comprising the DarkSword iOS exploit chain, actively used by commercial surveillance vendors and suspected state-sponsored threat actors against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.

Known Exploited(Mar 20, 2026)✓ Fix Available
💡

This section explains the vulnerability in everyday language, so anyone can understand the risk and impact.

Imagine visiting a website that secretly crashes a part of your iPhone's brain — before you've even clicked anything. That's essentially what CVE-2025-31277 allows.

WebKit is the engine under the hood of Safari and all iOS browsers (yes, even Chrome and Firefox on iPhone use it — Apple requires it). This vulnerability is a "buffer overflow," meaning an attacker can trick WebKit into writing data outside its allowed memory space — like scribbling outside the lines of a coloring book, except the "scribble" is malicious code that takes over your device.

Google's Threat Intelligence Group discovered this as part of a six-vulnerability exploit chain called **DarkSword**. Multiple hacking groups — including commercial spyware vendors and suspected Russian and other state-backed hackers — have been using DarkSword in the wild since at least November 2025. Targets include individuals in Saudi Arabia, Turkey, Malaysia, and Ukraine.

Once DarkSword lands on your device, it deploys one of three malware families: GHOSTBLADE, GHOSTKNIFE, or GHOSTSABER — all built for covert surveillance.

**The good news:** Apple has patched this in iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, Safari 18.6, watchOS 11.6, tvOS 18.6, and visionOS 2.6. Update now.

Affected Products

7affected products identified
ProductVendorVersionPatched
>SafariApple< 18.618.6
>iOSApple< 18.618.6
>iPadOSApple< 18.618.6
>macOS SequoiaApple< 15.615.6
>watchOSApple< 11.611.6
🔧

Remediation

Fix Available

Update all Apple devices immediately: iOS/iPadOS 18.6, macOS Sequoia 15.6, Safari 18.6, watchOS 11.6, tvOS 18.6, visionOS 2.6. Settings → General → Software Update. High-risk individuals unable to update immediately should enable Lockdown Mode.

CVSS Score
8.8
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Vector (v3.1)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Quick Info
CVE IDCVE-2025-31277
Severityhigh
FixAvailable
KEVListed
PublishedMar 24, 2026