Apple patches 'Coruna' exploit

By
Follow google news

In older iOS and iPadOS versions.

Apple has backported patches for iOS 15 and 16 devices just this week, with iOS 15.8.7 and iOS 16.7.15 released to address the kernel and WebKit vulnerabilities associated with Coruna for devices that cannot update to the current iOS release.

Apple patches 'Coruna' exploit

The company's equivalent generation iPadOS operating systems were also patched.

Google's Threat Intelligence Group (GTIG) identified Coruna in early 2025, with security vendor iVerify conducting independent parallel analysis and publishing its findings simultaneously with Google in early March 2026.

The Coruna kit packs 23 exploits across five complete iOS exploit chains targeting devices running iOS 13 through 17.2.1, with the most advanced techniques using non-public exploitation methods and mitigation bypasses.

GTIG first observed the kit in February 2025 in use by a customer of a commercial surveillance vendor, before tracking it to watering hole attacks by UNC6353.

This is a suspected Russian state-sponsored group attacking Ukrainian websites, with GTIG ultimately tracking Coruna to a financially motivated Chinese criminal group deploying it via fake cryptocurrency exchange and gambling sites.

Source: GTIG

Researchers gained insight into the kit's internals after a threat actor mistakenly deployed a debug version, exposing internal code names and documentation embedded throughout the framework.

 

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

Researchers uncover 'Darksword' iPhone spyware

Researchers uncover 'Darksword' iPhone spyware

Stryker contains cyber attack on its Microsoft environment

Stryker contains cyber attack on its Microsoft environment

Exploited Google Chrome zero-days added to US must-patch list

Exploited Google Chrome zero-days added to US must-patch list

Log In

  |  Forgot your password?