Three critical vulnerabilities in iOS and macOS have been added to the Known Exploited Vulnerabilities catalog as the "DarkSword" spyware campaign intensifies.

What a CISA KEV listing changes for Apple platforms

When CISA adds vulnerabilities to the Known Exploited Vulnerabilities catalog, the signal is operational, not theoretical: the flaws are already being used in real attacks. In this case, three critical issues affecting iOS and macOS were added in connection with the DarkSword spyware campaign. That combination—active exploitation plus a named spyware effort—raises the priority above a typical patch-cycle item. Agencies and regulated organizations often treat KEV entries as hard deadlines for remediation; everyone else should treat them the same way in practice, even if no formal mandate applies.

DarkSword-style campaigns typically aim for silent, high-value access: install spyware, persist, and exfiltrate data without obvious user-facing symptoms. A KEV update does not invent that risk; it confirms that the path into the device is already in use. Waiting for a quiet maintenance window is the wrong posture once exploitation is cataloged.

How spyware campaigns use platform flaws

Spyware operators prefer chains that work with little or no user interaction—links, messages, or other delivery paths that trigger vulnerable code paths in the OS or system services. Critical flaws in iOS and macOS matter because those systems hold credentials, messages, photos, and session tokens. Once spyware is on the device, the operator may not need further user mistakes; the compromise itself becomes the ongoing risk.

Three critical vulnerabilities in one update also matter for defense. Attackers often combine multiple bugs so that fixing only one link still leaves a working chain. Treat the set as a single incident response problem: patch everything covered by the update, then verify that devices actually received and applied it—not merely that an update was announced.

Practical steps for users and teams

Prioritize fully updating every Apple device you manage: phones, tablets, and Macs. Enable automatic updates where policy allows, and for fleets, confirm compliance through your mobile device management or inventory tools rather than relying on self-reports. After updates, review whether any high-risk users (executives, journalists, developers with production access, people handling sensitive customer data) show signs of compromise: unexpected configuration profiles, unfamiliar configuration changes, or unexplained battery and network activity that does not match normal use.

  • Apply the latest available system updates on all iOS and macOS devices as soon as they can be rolled out safely.
  • Restrict sideloading, untrusted profiles, and unmanaged device enrollment on high-risk accounts.
  • Rotate credentials and session tokens for accounts used on devices that were offline or unpatched during the exploitation window.
  • Escalate devices with unexplained persistence or monitoring behavior to formal incident response rather than a simple reboot-and-hope approach.

What security and IT should document from this KEV update

Record which assets run iOS or macOS, when the KEV-related updates were applied, and which systems remain outstanding. If your organization follows binding operational directives or similar rules, map this KEV entry to those timelines and track exceptions with owners and dates. For consumer and small-team contexts, the same discipline still helps: note the Mar 21 KEV context so you can later answer whether a device was patched before or after exploitation was publicly confirmed.

DarkSword’s intensification does not require panic, but it does require action. Critical, actively exploited flaws on widely deployed Apple platforms are a patch-first event. Update devices, verify the update stuck, and treat residual uncertainty on high-value targets as a reason to investigate—not as a reason to delay.

Automate Your Content with AI Video Generator

Try it Free →