Ledger CTO Warns of DarkSword Safari Attack That Can Steal Crypto Keys From iPhones

Ledger warns of a Safari attack via DarkSword
Table of Contents

TL;DR:

  • Charles Guillemet, Chief Technology Officer at Ledger, issued a public alert on September 21, 2026, regarding the DarkSword exploit chain targeting Safari.
  • The threat chains six iOS security flaws that compromise the JavaScriptCore engine, bypass sandbox isolation, and exploit the system kernel.
  • Google confirmed that the original vulnerabilities in the chain were patched starting with iOS 18.3, while Apple continues to roll out security fixes in subsequent versions.

This Monday, Charles Guillemet issued a warning regarding Safari-targeted attacks executed through DarkSword. The Ledger CTO pointed out that browsing malicious websites could compromise iPhone devices and expose digital assets.

Guillemet explained that the exploit breaks through Apple’s security layers before gaining deep access to the device. The attack vector is triggered simply by visiting an infected web page through the native browser. The executive stated that attackers can execute arbitrary code without requiring manual downloads from the victim.

Ledger warns of a Safari attack via DarkSword

Intrusion Mechanism and Risks for Crypto Wallets

Under normal operating conditions, web content opened in Safari remains strictly confined within an isolated sandbox environment.

DarkSword bypasses these barriers through a coordinated exploit sequence. The intrusion begins in JavaScriptCore, Safari’s processing engine, where the attacker seizes control of the browsing process. Next, the malicious code bypasses Apple’s Pointer Authentication Codes (PAC)—designed to prevent software execution hijacking—allowing it to break out of the sandbox.

The technical report indicates that the final stage compromises the iOS kernel. Once this privileged access is achieved, the malware gains read access to the system keychain, messages, local files, and application logs.

Guillemet emphasized that this intrusion facilitates the exfiltration of recovery phrases, cryptographic seeds, or credentials improperly stored in screenshots and note apps. In light of this scenario, the executive reiterated the recommendation to keep private keys isolated on dedicated hardware devices.

Security documentation previously disclosed by Google indicates that the initial flaws in this chain were addressed in earlier iOS updates. Nevertheless, cybersecurity analytics firms have warned that variations of these exploits could linger on unpatched devices.

Apple continued rolling out cumulative patches aimed at mitigating additional vulnerabilities in WebKit. Security teams recommend verifying patch availability in system settings or proactively enabling Lockdown Mode to neutralize the execution of unverified web code.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews