CVE-2025-31200
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a memory corruption issue was addressed with improved bounds checking. EPSS 19% (97th percentile).
CISA federal remediation date May 8 · date passed
Vulnerabilities & Exploits · Credential Theft
iVerify said a new DarkSword variant called P7 DarkSword is being used in the wild against iOS 18.4–18.7, and it chains three iOS flaws — CVE-2026-31001, CVE-2025-24201, and CVE-2025-31200 — to break out of the browser and land in SpringBoard, the iPhone process that runs the home screen and app launches.
Once it gets there, the implant can work from the middle of the phone instead of inside one app. iVerify says P7 trims its footprint, pulls keychain data and crypto-wallet data on-device, and adds two-way command-and-control, which means the compromise can expose device-wide secrets and keep accepting instructions after the initial lure.
For organizations that rely on iPhones for sign-in or store high-value credentials on the device, the exposure is not confined to a single app session. The reporting says the kit sits at the UI layer, so a phone that looks normal to the user can still carry secrets an attacker can reuse elsewhere.
1 source · 6h ago
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a memory corruption issue was addressed with improved bounds checking. EPSS 19% (97th percentile).
CISA federal remediation date May 8 · date passed
Known exploited · CISA KEV
CVSS 10 CRITICAL: an out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. EPSS 4% (90th percentile).
CISA federal remediation date Apr 3 · date passed
The Hacker News
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
P7 DarkSword adds on-device keychain and crypto wallet data theft to the iOS exploit kit, alongside two-way C2 communication.
originalPart of the PlainSec briefing for 2026-10-09
Every edition of this story: P7 DarkSword reaches into SpringBoard and wallet data