Skip to content

Security1 publisher2 min readPublished

Fake iPhone Duo preorder page fires the DarkSword exploit chain the moment it loads

Scammers wrapped the leaked DarkSword exploit chain in a fake iPhone Duo preorder page that attacks the moment it opens, before any form, tap, or download. Apple has already patched the flaws it uses, so a current iOS build is what protects a phone here.

The Watch · Security desk

Illustration accompanying Fake iPhone Duo preorder page fires the DarkSword exploit chain the moment it loads

What happened

  • The page copies Apple's look, down to a 'Copyright (c) 2026 Apple Inc.' footer, and dangles a $500 'Authorized Partner Exclusive' voucher plus AppleCare+ for anyone who fills in a preorder form.
  • In the captured version the form is inert: its submission handler never reads or sends what you type, and the page fakes a 'Pre-Order Successful' message while the exploit runs behind it.
  • An invisible frame reads the phone's iOS version, picks matching code, and DarkSword tries to get past the iPhone's protections and gain deep access without waiting for a tap.
  • If it breaks in, the payload hunts for crypto wallets such as MetaMask, Phantom and Trust Wallet and tries to lift saved credentials from the phone's keychain.
  • Malwarebytes said it analyzed the captured code but did not run it on an iPhone or watch data leave one.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Exposure is set by patch level, not user behavior: iVerify put up to 270 million devices in the targeted iOS 18.4 through 18.6.2 range in March, though that count predates this page and does not measure what it can hit.
  • constraint Anti-phishing advice misses this page; the control that works is a current iOS build, which Apple says blocks the reported attack.
  • precedent A launch lure aimed at people shopping for a new iPhone lands on exactly the group most likely to still be on an older, unpatched one.

Google described the DarkSword chain in March, Apple patched the vulnerabilities it reported, and several parts of this page's code match that chain [12]. The page hides that leaked chain and uses it to try to break into vulnerable iPhones [2].

On an iPhone the page reopens the link in Safari, the browser the chain targets, and any browser it does not recognize as Safari gets a "Browser Restricted" notice [6]. A current phone can still be steered there. Safari can report an older iOS version to a website, so even an updated iPhone may load the attack code [14].

Once it runs, the payload can be told to pull files, full-size photos, contacts, messages and the contents of Apple Notes, and it deletes diagnostic reports that would otherwise help investigators spot the intrusion [9][10]. The code is built to run inside a system process, but it may stop before the phone restarts, and Malwarebytes found no mechanism that brings it back after a reboot [15].

Apple announced the iPhone Duo on September 9 and does not open preorders until October 16, so the page sells a preorder that cannot exist yet [1][16]. Small details give it away: 6.3-inch and 6.9-inch models in colors Apple does not sell, a countdown that resets on every load, and privacy, terms and sales links that go nowhere [17].

What to watch

  • Whether hosts or Apple take the fake preorder page down before the October 16 preorder window opens.
  • Whether anyone confirms the exact iOS range this page targets, given its files also include code for older versions.
  • Whether the same DarkSword lure reappears against other product launches or in other regions.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories