Fake iPhone Duo preorder page reportedly targets iPhones
Malwarebytes says a fake iPhone Duo preorder page is using the DarkSword exploit to attack vulnerable iPhones as soon as users load the site, without requiring a click, download or form submission. The reports do not establish how many people visited the page or whether any users’ data was confirmed stolen. The page advertises a $500 voucher for the foldable phone, which Apple has said will not be available for preorder until October 16, 2026. Malwarebytes says the exploit can target iPhones running iOS 18.4 through 18.6.2. Apple says devices running the latest versions of iOS 15 through iOS 26 are protected. The specific range affected by this campaign has not been independently established in the reports. According to Malwarebytes, the attack attempts to collect passwords and other saved credentials, Apple Notes, cryptocurrency wallet data and personal information such as messages, contacts, call history, email and location data. Those are reported capabilities, not confirmation that the information was taken from any victim. The preorder page is designed to resemble an Apple site and offers a form to register interest.