CISA Orders Federal Agencies to Patch DarkSword Spyware Vulnerabilities in Apple Devices by April 3

CISA has added five actively exploited security flaws to its Known Exploited Vulnerabilities catalog — including three Apple vulnerabilities linked to the sophisticated DarkSword iOS exploit chain — ordering all US federal agencies to patch by April 3, 2026.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
CISA issues urgent patch deadline for Apple iOS DarkSword exploit chain vulnerabilities affecting federal agencies and enterprises

CISA issues urgent patch deadline for Apple iOS DarkSword exploit chain vulnerabilities affecting federal agencies and enterprises

The US Cybersecurity and Infrastructure Security Agency (CISA) has added five new security flaws to its Known Exploited Vulnerabilities (KEV) catalog, issuing a firm deadline of April 3, 2026 for all Federal Civilian Executive Branch (FCEB) agencies to remediate the issues. Three of the five vulnerabilities are linked to a sophisticated iPhone exploit chain dubbed DarkSword — a multi-stage attack framework capable of achieving full device compromise across Apple's ecosystem with minimal user interaction.

The additions follow research published by Google Threat Intelligence Group (GTIG), iVerify and Lookout documenting how DarkSword chains multiple vulnerabilities together to deliver a trio of malware families — GhostBlade, GhostKnife and GhostSaber — designed for data theft, surveillance and persistent device access.

What Is DarkSword?

DarkSword is a multi-stage attack designed to achieve full device compromise across Apple's ecosystem, including iOS, iPadOS, macOS, watchOS, tvOS and visionOS. The attack targets core system components and requires minimal user interaction, making it particularly dangerous — typically beginning when a victim visits a malicious or compromised website through Safari or an in-app browser.

According to Google's technical analysis, DarkSword is built entirely in JavaScript — an unusual design choice that nonetheless allowed it to bridge into native interfaces and exploit iOS internals without relying on unsigned binary payloads. The chain uses six vulnerabilities spanning memory corruption bugs in JavaScriptCore, a bypass for Apple's pointer authentication protections, and two kernel-level bugs that enable the final rise to full device control.

The group behind DarkSword is tracked under the identifier UNC6353, with a suspected Russian espionage connection, while a separate threat actor tracked as UNC6748 — a customer of Turkish commercial surveillance vendor PARS Defense — has also been observed deploying the chain. Security researchers have additionally noted signs that large language model (LLM) tools have been used to extend DarkSword's functionality, suggesting a new frontier in AI-assisted exploit development.

The Five Vulnerabilities

CISA has added the following five vulnerabilities to its KEV catalog, all of which are being actively exploited in the wild: CVE-2025-31277 (Apple Multiple Products Buffer Overflow), CVE-2025-32432 (Craft CMS Code Injection), CVE-2025-43510 (Apple Multiple Products Improper Locking), CVE-2025-43520 (Apple Multiple Products Classic Buffer Overflow), and CVE-2025-54068 (Laravel Livewire Code Injection).

Beyond the Apple flaws, CVE-2025-32432 in Craft CMS carries a top-tier severity score and allows attackers to remotely execute harmful code without authentication — a critical risk for organisations running the popular content management platform. The final vulnerability, CVE-2025-54068 in Laravel Livewire, has been linked to attacks by the Iran-nexus APT group MuddyWater — formally attributed to Iran's Ministry of Intelligence and Security (MOIS) — which has historically targeted telecommunications, government and energy sectors across the Middle East, Europe and North America.

The Patch Deadline and What Organisations Should Do

Under Binding Operational Directive (BOD) 22-01, FCEB agencies have been ordered to secure their devices by April 3, 2026. CISA's directive states: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."

While the mandate formally applies only to federal agencies, CISA has strongly urged all private sector organisations and individual users to treat these vulnerabilities as an immediate priority. If patches cannot be applied to specific systems, security teams are instructed to discontinue use of those products entirely to prevent potential network compromise.

All three Apple CVEs have been patched in the latest iOS releases and currently affect only devices running iOS 18.4 through 18.7. Users and administrators should ensure all Apple devices are updated to the latest available software version without delay.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.