Fake iPhone Duo preorder site exploits unpatched iPhones
Security researchers at Malwarebytes discovered a fraudulent iPhone Duo preorder website using the DarkSword exploit chain to attack older, unpatched iPhones. Simply loading the website is enough to trigger the exploit, which attempts to steal saved passwords, cryptocurrency wallet data, photos, and personal notes. The scam specifically targets iPhones with iOS versions 18.4 through 18.6.2 and does not affect iPads or Macs, according to Malwarebytes.
- Malwarebytes found a cloned iPhone Duo preorder page
- The page delivers malware via the DarkSword exploit chain
- Affects iPhones on iOS 18.4 to 18.6.2 only, not iPad or Mac
- No user action needed beyond opening the scam website
- Malware tries to access crypto wallets, credentials, and notes
Sources covering this
How it unfolded
- CNET Look Out for This iPhone Duo Preorder Scam That Can Steal Your Data
- Tom's Guide Scammers are using iPhone Duo pre-orders to try and steal your passwords — here's how to stay safe
- 9to5Mac Fake iPhone Duo preorder page can steal crypto wallet data and more
- AppleInsider PSA: Do not open links to an early iPhone Duo pre-order page
In this story
More in Cybersecurity
AI accelerates discovery of high-risk software vulnerabilities
Google’s Threat Intelligence Group reported that monthly vulnerability disclosures have doubled this year, increasing from 5,045 in…
OpenAI disrupts novel AI distillation attack it links to China
OpenAI announced it has stopped a coordinated attempt to extract and distill reasoning capabilities from its AI systems, attributing a…
Cisco SD-WAN Manager vulnerability actively exploited
Cisco has disclosed a critical security vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is being exploited by attackers.
Unpatched Zimbra flaw exploited to steal emails and credentials
A critical security vulnerability in Zimbra Collaboration Suite has been exploited by attackers to access emails and authentication data…