Vulnerabilities · 5h ago

P7 DarkSword reaches into SpringBoard and wallet data

iVerify said a new DarkSword variant called P7 DarkSword is being used in the wild against iOS 18.4–18.7, and it chains three iOS flaws — CVE-2026-31001, CVE-2025-24201, and CVE-2025-31200 — to break out of the browser and land in SpringBoard, the iPhone process that runs the home screen and app launches.

Once it gets there, the implant can work from the middle of the phone instead of inside one app. iVerify says P7 trims its footprint, pulls keychain data and crypto-wallet data on-device, and adds two-way command-and-control, which means the compromise can expose device-wide secrets and keep accepting instructions after the initial lure.

For organizations that rely on iPhones for sign-in or store high-value credentials on the device, the exposure is not confined to a single app session. The reporting says the kit sits at the UI layer, so a phone that looks normal to the user can still carry secrets an attacker can reuse elsewhere.

CVE-2025-31200

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a memory corruption issue was addressed with improved bounds checking. EPSS 19% (97th percentile).

CISA federal remediation date May 8 · date passed

CVE-2025-24201

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: an out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. EPSS 4% (90th percentile).

CISA federal remediation date Apr 3 · date passed

CVE-2026-31001

NVD KEV

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-09

Editions

Related stories