Apple has released iOS 18.7.7 and iPadOS 18.7.7 to devices that support iOS 18, taking the unusual step of issuing a critical security patch to all users who have chosen not to upgrade to iOS 26.
The update, carrying build number 22H340, specifically targets a severe vulnerability exploited by a spyware toolkit known as DarkSword. The underlying code for the exploit recently surfaced on public sites like GitHub, giving various hacking groups a ready-made tool to deploy web-based attacks that can silently compromise devices when a malicious webpage is loaded, as detailed in our DarkSword report. Apple had already closed this security gap for anyone running iOS 26, but this unexpected release brings those same protections to iOS 18 users.
Historically, Apple reserves updates for older firmware strictly for devices whose hardware cannot support the latest software release. By offering this patch to all iOS 18 users, the company is addressing the roughly one-quarter of active iPhone owners who have held off on installing iOS 26. Many of these users have delayed the upgrade due to app compatibility concerns, storage limits, or a preference for the older interface.
To ensure more users apply the fix, Apple is presenting it differently from a typical update. Devices currently running older versions of iOS 18 will receive an additional, specific alert urging them to install the firmware as a Critical Security Update. Users with auto-update enabled will receive the patch automatically, while others can choose between applying the iOS 18 fix or upgrading to iOS 26.