My old iPhone is still on iOS 27 because I never installed any updates after setting it up, and I’m now trying to work out whether DarkSword can affect it. I noticed the issue after reading about DarkSword while clearing old browser tabs; the phone had been sitting in a kitchen drawer and is now used mainly for music in the car.
I checked the software screen and confirmed iOS 27, but I have not seen unusual pop-ups, battery drain, or unfamiliar apps. Does never updating make this phone less exposed because nothing newer was installed, or more exposed because security fixes may be missing? What should I check before connecting it to Wi-Fi again?
Never updating does not make an iPhone safer. It leaves known security holes unfixed. There is a version mix-up here, though: iOS 27.0 was released on September 14, 2026, so a phone showing that under Settings > General > About is running a current release, not an old untouched installation. Automatic updates may have installed it. The documented DarkSword chain targeted iOS 18.4 through 18.7, not iOS 27.
Before reconnecting, use Airplane Mode and verify the iOS version and iPhone model under About. Check Settings > General > VPN & Device Management for profiles you do not recognize. Then make an encrypted cable backup and use Finder on a Mac or Apple Devices on Windows to check for an update. Updating through a trusted computer avoids browsing on the phone while it is potentially behind on patches.
No pop-ups, battery drain, or strange apps is reassuring but not proof, since this kind of attack can be quiet. If the screen actually says an 18-series version rather than 27, update before using Safari. If it genuinely says 27.0, DarkSword as currently documented is not the issue I would worry about. Keep automatic security updates enabled instead of preserving the original software.
Don’t change passwords on the possibly affected phone. @zeropilot is right that the version you quoted does not match the documented DarkSword target range, but if you opened a suspicious link or entered credentials, use another trusted device to secure your Apple Account, email, and financial accounts. That is a more realistic concern than DarkSword silently surviving on a newer iOS release.
The missing fact is whether the phone had any real exposure. Reading an article about DarkSword does nothing to the phone. A suspicious message, link, attachment, configuration profile, or physical access would give you a reason to investigate.
I’m skeptical that DarkSword is the likely problem here. The strange version history sounds more like automatic updating or a mistaken reading of the software field. Check the exact iPhone model too, since that determines which security releases it can receive. If the model has reached the end of support, “no update available” does not necessarily mean it is safe for banking, email, or account recovery.
If you have a credible reason to think it was targeted, updating alone is not the highest-confidence cleanup. Save essential photos and documents, erase the phone, and set it up as new rather than immediately restoring every setting. For an ordinary suspicious-link incident, that may be excessive. For someone in a higher-risk role, such as journalism or political work, preserve the phone and get specialist help before wiping it, since erasing it destroys evidence.
So the practical answer is: you are not endangered merely because you never knowingly updated, but avoiding updates is not protection. Confirm the model, version, and what actually happened before treating this as a DarkSword infection.
Realistically, you can’t trust the version number to tell you if the phone is clean. The version number just says whether particular documented chains of DarkSword would work on it. If the About screen actually displays the current major iOS release, then that documented chain of DarkSword isn’t the one you’ve got. But “I never updated it” can’t possibly be what they mean if that’s the case; it was updated automatically during setup or a restore.
There’s a difference between being vulnerable and being infected, though. The target phone needed to have been tricked into executing attacker-controlled web content while running the compromised iOS version for DarkSword to get on there. Skimming an article about it isn’t going to do that. Unless they followed some sketchy link or got an Apple threat notification somehow, they have much more reason to believe their phone has been wiped by something else than that they’re secretly running DarkSword.
For the lazy option, restarting the phone and applying all updates that appear, including point releases, should be fine. A restart will kill some malware that only runs in-memory, but in general it doesn’t fix security issues and shouldn’t be considered confirmation that the phone isn’t infected. If the phone can’t get the latest security patches, Lockdown Mode might help reduce exposure, but it can’t turn unsupported software into supported secure software.
An actual Apple threat notification changes some things. They should check this using their Apple Account on another device without clicking any links in the notification first, though, before deciding that it wasn’t some weird version history coincidence that let DarkSword get on their phone.
Odds are you are chasing a threat that was never aimed at your phone in the first place. If the About screen really shows the current major release, DarkSword’s known method simply had nothing to bite on, because it went after a much older branch. So the more honest question isn’t ‘am I safe from DarkSword’ but ‘why does my phone say it was never updated when the version proves otherwise.’
That gap is the actual clue. A phone doesn’t arrive at a current release by sitting untouched. It got there during setup, an overnight automatic update, or a restore you might not have thought of as an update. @tech_anna62 and @zeropilot already nailed that contradiction, so I won’t relitigate it. Where I’d steer you differently is on effort: don’t build a whole incident-response ritual around a memory of what version you thought you were on. Open Settings, read the model and version slowly, and screenshot it. Half these panics come from misreading the software line or confusing model numbers.
If nothing weird actually happened, no dodgy profile, no link you tapped, no Apple threat alert, then let it update on its own and move on. The one thing I’d genuinely watch is the model age. A newer OS version on hardware that has quietly aged out of security patches can lull you into thinking you’re covered when you’re only cosmetically current. That matters way more for your banking and account recovery than DarkSword ever will here.
Do not install any apps offering to “scan for DarkSword” – regular iOS apps cannot scan the system deep enough to confirm the absence of such a threat. A scan result showing nothing would be more reliable evidence than your memory of the update.
Trust the version stated in Settings rather than your recollection of the update. If About shows the latest possible version and Software Update does not detect any security problems, the described chain of exploits is not applicable to your phone. This does not mean that your phone is completely safe from any possible attack, but until you get a direct confirmation of an exploit, it is best to consider that this particular one is not targeting your device.
I would check your Apple Account from another device to see if anything suspicious appears in the signed-in devices list, recent activity, recovery options area, or anywhere else on the account’s privacy settings. Delete any unauthorized devices and change the password on the account if necessary. This will rule out the possibility of your account being compromised on another device, which many users mistake for signs of a phone hack.
Do not waste time searching Safari history for the suspicious page – a hacked legitimate website could also be disguised as a malicious one, and the lack of history would not prove anything either way. Without detecting any Apple-related threats and suspicious activity on your accounts, it is best to simply update the phone and continue using it as usual. If you did get a legitimate threat notification or have reason to believe you are being specifically targeted, it is best to avoid consumer-grade scanning software and get your phone checked for potential security issues before wiping it.
An ‘old iPhone’ that displays the current major release usually isn’t old at all, and that’s the detail worth chasing before anything else. Apple drops older hardware from each big release. If your phone genuinely couldn’t have installed the latest version, then what you’re reading on the About screen is either a point release of an older branch or a misread. So the ‘old phone on newest OS’ story tends to collapse the moment you check what that model is actually eligible for.
@datahacker8984 and @shadowwizardedge already hit the model-age point, and I agree with them, but I’d push it one step further. Look up the oldest supported model for the release you think you’re on. If your phone isn’t on that list, you are not on that version, full stop. That single check kills most of this panic faster than any profile hunt.
Where I part ways a little is with all the incident-response energy in here. Backups over cable, erase and set up as new, preserve for forensics. That’s the correct playbook for someone with an actual reason to think they were hit, but nothing you described qualifies. You read an article. That’s it. Building a whole cleanup routine off a vague memory of an update history is effort spent on a threat that never had a foothold.
The one habit I’d flag that nobody mentioned: your phone offers to install updates but also lets you keep dismissing them, and a lot of people who swear they ‘never updated’ have actually been tapping Later for months while security patches slipped in overnight anyway. Your memory of your own update behavior is the least reliable thing in this whole thread. Trust the screen, confirm the model, and if it’s eligible for the current version, let it finish patching and get on with your day.