Chips & Hardware
Leaked hacking toolkits put millions of iPhones and iPads at risk
Leaked hacking toolkits, including some linked to a defense contractor unit, are putting millions of iPhones and iPads running older software at risk of data theft.
A major leak of advanced hacking toolkits has put millions of iPhones at risk of data theft across the world. The leaked tools, dubbed Coruna and DarkSword, represent severe hacking threats that have been used in hacking campaigns to steal private data from Apple devices. With more than 2.5 billion active devices around the world, the leak of this malicious code on the code-sharing site GitHub has made these exploits accessible to a wider range of actors.
The toolkits target specific versions of Apple’s operating system. Security researchers have noted that Coruna’s exploits can hack iPhones and iPads running iOS 13 through iOS 17.2.1, which was released in December 2023. Meanwhile, security researchers with Google have found that DarkSword contains exploits capable of hacking more recent devices running iOS 18.4 and 18.7, which were released in September 2025. TechCrunch reported that at least some parts of the Coruna toolkit were originally developed by Trenchant, a hacking and spyware unit within the U.S. defense contractor L3Harris. While Coruna has been linked to attacks in Russia, researchers have observed DarkSword hacking campaigns targeting users in China, Malaysia, Turkey, Saudi Arabia, and Ukraine.
The threat from DarkSword is particularly immediate because part of the toolkit was leaked and published on GitHub. According to Justin Albrecht, principal researcher at mobile security firm Lookout, the leaked tools are “essentially plug-and-play” for anyone looking to launch attacks. Despite the risk, GitHub has chosen to keep the code online. Jesse Geraci, GitHub’s online safety counsel, explained that while the platform prohibits content supporting active malware campaigns, it does not ban posting source code that could be used to develop exploits, citing its educational value for the security community.
Apple has stated that users running the latest versions of iOS 15 through iOS 26 are already protected against these hacking toolkits. However, Apple’s statistics show that almost one-in-three iPhone and iPad users are still not running the latest iOS 26 software, leaving potentially hundreds of millions of devices running out-of-date software at risk. Security research firm iVerify strongly recommends that users update to iOS 18.7.6 or iOS 26.3.1 to mitigate the vulnerabilities. For users unable or unwilling to upgrade, Apple noted that Lockdown Mode—an extreme security setting first introduced in iOS 16—blocks these specific attacks. There has been no public evidence that hackers have to date ever been able to bypass Lockdown Mode protections.
Why it matters
The proliferation of government-grade hacking tools into the public domain creates an immediate security risk for users around the world. It highlights the fragility of digital security when sophisticated exploits leak, potentially exposing hundreds of millions of out-of-date devices to data theft.