Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster


Apple on Wednesday will issue software updates to devices still running iOS 18 to protect them from an exploit called DarkSword, which can silently take over an iPhone if it visits a website infected with the malicious code.

apple-lock-security-bug-vulnerability-fix-privacy.jpg

Devices on iOS 26 are already protected against DarkSword, but in a surprising move for Apple, its latest critical update is designed to specifically protect vulnerable iOS 18 users who have consciously decided not to update to iOS 26, even though their iPhone model supports it. Some users may be hesitant to upgrade to ‌iOS 26‌ because of the Liquid Glass design overhaul that makes major changes to the iPhone interface.
"Tomorrow we are enabling the availability of an iOS 18 update for more devices so users with auto-update enabled can automatically receive important security protections," an Apple spokesperson told Wired. "We encourage all users with supported devices to update to iOS 26 to receive our most advanced protections."
iPhone users can install the updates by opening up the Settings app, going to General, and selecting the Software Update option. Those with automatic updates turned on will see the new software installed automatically.

It's the second time in the last few weeks that Apple has pushed a critical update to iPhones running out-of-date software. On March 11, Apple issued a patch to protect users from a different iOS hacking toolkit known as Coruna. The patch was for older devices that can't run iOS 26. Apple recommended that everyone else update to the latest OS version that their device supports.

The practice of protecting an older operating system version is known in the cybersecurity industry as "backporting," but it's not something that Apple typically does if a newer, compatible version of iOS has the same protections already baked in.

According to Google, DarkSword has been used by various hacker groups to break into the iPhones of users in Malaysia, Saudi Arabia, Turkey, and Ukraine. Last week, the exploit kit was posted to open source code repository GitHub, making it even more likely to be used by bad actors.

Article Link: Apple to Issue Rare iOS 18 Software Update for DarkSword Exploit
 
when did it become not normal for the previous version to get security updates?

it's news when older, actually unsupported OS versions get an update because a security bug is deemed important enough (although it also just proves they could go on supporting them anyway). but the previous version to current getting them should not be news.
 
when did it become not normal for the previous version to get security updates?
It was never normal. The previous version receives updates for a limited time (three months or so), but after that only devices that can’t update to a newer major version will receive security updates. What’s different with this announcement is that apparently all devices will be receiving the update.

The limited-time updates started with iOS 14. Before that, there was no overlapping window at all.
 
I don't get it, how is this rare and anormal? Don't "older" sw versions get security updates too? Especially for something this bad? And wasn't 18 released like year? What's the deal,
Normally only devices that can’t upgrade to iOS 26 receive the updates (iPhone XS and XR). If you have a newer device and deliberately didn’t want to upgrade to iOS 26, you were out of luck. The news is that Apple apparently will be making an exception now.
 
Is this an April Fools joke? Only seeing the option to upgrade to iOS 26.4, no iOS 18 update available…sigh.
Maybe it will be offered later today?
A man can hope, right?
 
  • Love
Reactions: bigandtasty
Wow, that’s unexpected at this point. Kudos if they actually do this. And I feel for those who gave up and already downgraded to iOS 26.

On the other hand, today is April’s Fools.
Luckly it’s not April Fool.
Article came yesterday, so 31 of March.

Source: https://www.wired.com/story/apple-w...ect-ios-18-users-from-darksword-hacking-tool/

After post from a Wise Man
 
Are you f***ing kidding me?!
Not 6 hours ago, I updated to f***ing Liquid Ass, because of these exploits.

I HATE Apple so much right now.
Damned if they do, damned if they don’t.
If they back port security updates, it’s because…


They must really want that age verification everywhere.
And…

I’d this apple admitting that LG is a mess
But if they don’t, it’s a very personal and intentional slight at those who don’t like the new interface, despite the fact that this has been their policy since iPhoneOS 1.1.5 wasn’t released for the original iPhone and only 2.0 was.
There is literally no winning.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.