Coruna iPhone exploitation and Apple response
Case score 63
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 63
- Main story score
- 58
- Related evidence lift
- +5 / 20
- Contributing updates
- 2
- Context updates
- 2
- Campaign Base Coruna iPhone exploit activity with UNC6353 and UNC6691 reuse across watering-hole and lure-site delivery. main
- Campaign Adds direct exploitation context for Coruna reuse across Ukraine watering holes and fake finance/crypto sites. contributes
- Vulnerability Technical grounding for the WebKit memory-corruption flaw used in Coruna-linked exploitation. context
- Security Patch Release Legacy-device backport for the Coruna-linked CVE-2023-43010 WebKit flaw. context
Overview
Latest development Open development history Kaspersky links Coruna to Triangulation-era exploit code Kaspersky reported that the Coruna iOS exploit kit is an updated version of the kernel exploit code used in Operation Triangulation, with shared kernel exploitation framework elements, support for Apple's A17, M3, M3 Pro, and M3 Max processors, checks for iOS 17.2 and iOS 16.5 beta 4, and delivery of five full iOS exploit chains and 23 exploits that can lead to PlasmaLoader (aka PLASMAGRID) after a compromised Safari visit.
-
Coruna iOS exploit kit identified across Apple iPhone targets
Google identified Coruna (aka CryptoWaters) as a new and powerful exploit kit targeting Apple iPhone models running iOS 13.0–17.2.1, and GTIG said it contained five full iOS exploit chains and 23 exploits built around device fingerprinting, WebKit RCE exploitation, and a PAC bypass. The same reporting also tied the framework to activity that circulated since February 2025, appeared on compromised Ukrainian websites in July 2025 through a hidden iFrame delivery path, and later surfaced on fake Chinese finance websites in December 2025 without geolocation constraints, while noting that the kit is not effective against the latest iOS.
-
Coruna iOS exploit kit linked to espionage and crypto theft
Coruna is a previously undocumented iOS exploit kit with 23 exploits and five full exploit chains that affected iOS 13.0 through 17.2.1 and included CVE-2024-23222. GTIG first observed related activity in February 2025, later saw UNC6353 use the same framework in summer 2025 watering-hole attacks against iPhone users visiting compromised Ukrainian websites, and attributed late-2025 activity on fake Chinese gambling and crypto websites to UNC6691. Google added identified sites and domains to Safe Browsing and recommended updating iOS or enabling Lockdown Mode.
-
Apple backports Coruna-linked fixes to older iPhone and iPad models
Apple backported the Coruna-linked CVE-2023-43010 fix to iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, and iPadOS 16.7.15 for older iPhone and iPad models that cannot update to the latest iOS version, including iPhone 6s, iPhone 7, iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), iPod touch (7th generation), iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation, while Google described Coruna as an exploit kit with 23 exploits across five chains targeting iPhone models on iOS 13.0–17.2.1.
-
Google details Coruna exploit kit scope
Google said Coruna features 23 exploits across five chains designed to target iPhone models running iOS versions between 13.0 and 17.2.1, adding new scope detail to the WebKit-linked exploit kit associated with CVE-2023-43010.