ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-32434
Integer Overflow in Apple iOS, iPadOS, macOS and watchOS Grants Kernel-Privilege Code Execution

CVE-2023-32434 is an integer overflow (CWE-190) in a kernel component of Apple's operating systems, caused by insufficient input validation. It is triggered when a malicious or compromised app processes input that overflows an integer value, allowing the attacker's code to escape the app sandbox. Successful exploitation lets an app execute arbitrary code with kernel privileges, the highest level of access on the device, giving full control of the affected iPhone, iPad, Mac or Apple Watch. All devices running iOS/iPadOS before 16.5.1 (or 15.7.7 on the iOS 15 branch), macOS Ventura before 13.4.1, macOS Monterey before 12.6.7, macOS Big Sur before 11.7.8, or watchOS before 9.5.2 (or 8.8.1) are affected, which spans Apple's entire device ecosystem. Exploitation is confirmed in the wild: Apple reported the flaw was actively exploited against iOS versions released before iOS 15.7, CISA added it to the KEV catalog on 2023-06-23, and news reports link it to the Operation Triangulation spyware campaign and commercial iOS exploit kits.

Do: Immediately update devices: iOS/iPadOS 16.5.1 (or iOS/iPadOS 15.7.7 for older models), macOS Ventura 13.4.1, Monterey 12.6.7, or Big Sur 11.7.8, and watchOS 9.5.2 (or watchOS 8.8.1 for older models), per the CISA KEV required action. Use MDM or device inventories to confirm fleet-wide patch compliance, prioritizing externally used and executive devices. Until patched, have users avoid installing or opening untrusted apps, since exploitation requires a local app as the delivery vector.

7.852% KEV
  • Apple iOS All versions prior to 16.5.1; iOS 15.x prior to 15.7.7
  • Apple iPadOS All versions prior to 16.5.1; iPadOS 15.x prior to 15.7.7
  • Apple macOS (Ventura) Prior to 13.4.1
  • +3 more
masswell over 1 billion devices (Apple's entire iPhone, iPad, Mac and Apple Watch installed base was exposed prior to the June 2023 updates)
CVE-2023-38606
Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS

CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected.

Do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines.

5.53% KEV
  • apple iPhone OS (iOS) iOS versions prior to iOS 15.7.8 and iOS 16 versions prior to iOS 16.6 (fixed in iOS 15.7.8 and iOS 16.6)
  • apple iPadOS iPadOS versions prior to 15.7.8 and iPadOS 16 versions prior to 16.6 (fixed in iPadOS 15.7.8 and iPadOS 16.6)
  • apple macOS Big Sur versions prior to 11.7.9 (fixed in macOS Big Sur 11.7.9)
  • +4 more
mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023)
CVE-2023-41974
Use-After-Free Kernel Code Execution Flaw in Apple iOS and iPadOS

CVE-2023-41974 is a use-after-free (CWE-416) memory-corruption vulnerability in Apple iOS and iPadOS that was addressed with improved memory management. It is triggered locally when an application on the device exercises the affected code path; the CVSS vector (AV:L/UI:R) indicates the attacker needs code running on the device and user interaction, but no network access or privileges. A successful exploit allows an app to execute arbitrary code with kernel privileges, giving the attacker full control over the affected iPhone or iPad. Anyone running iOS/iPadOS versions prior to iOS 17/iPadOS 17, including legacy 15.x devices prior to 15.8.7, is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, and public references tie it to the spy-grade 'Coruna' iOS exploit kit (23 exploits across five chains) used for financial crime, confirming exploitation in the wild.

Do: Update iPhones to iOS 17 and iPads to iPadOS 17, or apply the iOS 15.8.7 / iPadOS 15.8.7 emergency updates on legacy hardware that cannot run 17; inventory your fleet for devices on older builds and prioritize them, since the Coruna exploit kit reportedly targets older iOS versions. Until patched, avoid installing apps from untrusted sources, as exploitation requires running a malicious app. Federal agencies must meet the applicable BOD 22-01 required-action deadline for this KEV entry.

7.81% KEV PoC
  • Apple iPhone OS (iOS) iOS versions prior to 17; legacy iOS 15.x prior to 15.8.7 (fixed in iOS 17 and iOS 15.8.7)
  • Apple iPadOS iPadOS versions prior to 17; legacy iPadOS 15.x prior to 15.8.7 (fixed in iPadOS 17 and iPadOS 15.8.7)
mass≈1 billion+ devices in scope
CVE-2023-43000
Use-After-Free in Apple WebKit: Safari, iOS, iPadOS, macOS (CVE-2023-43000)

CVE-2023-43000 is a use-after-free vulnerability (CWE-416) in Apple's web content processing (WebKit) that was addressed with improved memory management. It is triggered when a device processes maliciously crafted web content, which per the CVSS vector requires user interaction such as visiting an attacker-controlled page. Successful exploitation causes memory corruption, and the high confidentiality, integrity, and availability scores indicate an attacker can likely gain code execution or data compromise on the target device. Any unpatched user of Safari, iOS, iPadOS, or macOS macOS versions earlier than the fixed releases is affected, including older iOS devices that Apple has now issued emergency updates for. The flaw is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-03-05, a public PoC reference ties it to the Coruna iOS exploit kit (a spy-grade kit with 23 exploits used for financial crime), and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile).

Do: Update affected systems to macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, or, for older devices still on iOS 15, iOS/iPadOS 15.8.7. Federal agencies under BOD 22-01 must apply vendor mitigations by the KEV deadline or discontinue use of affected products. Because exploitation requires user interaction with crafted web content, prioritize patching internet-facing and at-risk mobile fleets, and warn users to avoid untrusted links as an interim measure.

8.84% KEV PoC
  • Apple Safari Versions prior to Safari 16.6 (fixed in Safari 16.6)
  • Apple iPhone OS (iOS) Versions prior to iOS 16.6 (fixed in iOS 16.6); older devices on iOS versions prior to iOS 15.8.7 (fixed in iOS 15.8.7)
  • Apple iPadOS Versions prior to iPadOS 16.6 (fixed in iPadOS 16.6); older devices on iPadOS versions prior to iPadOS 15.8.7 (fixed in iPadOS 15.8.7)
  • +1 more
mass≈1 billion+ devices and users (Apple's active iPhone/iPad/Mac install base plus Safari users worldwide)
CVE-2023-43010
The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

NVD description · AI analysis pending
8.8<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2024-23222
Apple WebKit Type Confusion Enables Arbitrary Code Execution Across iOS, macOS, tvOS

CVE-2024-23222 is a type confusion flaw (CWE-843) in Apple's WebKit engine that allows arbitrary code execution when a device processes maliciously crafted web content, for example when a user is lured into loading attacker-controlled web pages in Safari or another WebKit-based view (the CVSS vector confirms user interaction is required). It affects a broad slice of the Apple ecosystem: Safari, iPhone OS/iPadOS on the iOS 15, 16 and 17 branches, macOS Monterey/Ventura/Sonoma, tvOS and visionOS, prior to the January 22, 2024 fixes. A successful attacker gains code execution on the target device with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). The flaw was fixed in Safari 17.3, iOS/iPadOS 17.3, and backported to iOS/iPadOS 15.8.7 and 16.7.5 for devices that cannot upgrade to iOS 17, plus macOS Monterey 12.7.3, Ventura 13.6.4, Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2024-01-23, one day after the fixes shipped, and is associated with the Coruna exploit kit, which reportedly chains multiple exploits to target iOS devices including older versions.

Do: Update all affected devices to Safari 17.3, iOS/iPadOS 17.3 (or the iOS/iPadOS 15.8.7 and 16.7.5 backports for devices that cannot run 17), macOS Monterey 12.7.3, macOS Ventura 13.6.4, macOS Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Prioritize endpoints used for web browsing and mobile users, since exploitation only requires a user to process crafted web content. The CISA KEV listing (added 2024-01-23) makes applying these vendor updates mandatory under the KEV required action, so verify fleet versions and confirm no devices remain on pre-patch builds.

8.811% KEV
  • apple Safari Versions prior to Safari 17.3 (fixed in 17.3)
  • apple iPhone OS (iOS) Versions prior to iOS 17.3; fixes backported in iOS 15.8.7 and iOS 16.7.5 for devices that cannot run iOS 17.3
  • apple iPadOS Versions prior to iPadOS 17.3; fixes backported in iPadOS 15.8.7 and iPadOS 16.7.5
  • +3 more
massover 1 billion active Apple devices (effectively Apple's entire unpatched iPhone/iPad/Mac/Apple TV fleet)
Full article610 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 12, 2026Vulnerability / Malware

Apple on Wednesday backported fixes for a security flaw in iOS, iPadOS, and macOS Sonoma to older versions after it was found to be used as part of the Coruna exploit kit.

The vulnerability, tracked as CVE-2023-43010, relates to an unspecified vulnerability in WebKit that could result in memory corruption when processing maliciously crafted web content. The iPhone maker said the issue was addressed with improved handling.

"This fix associated with the Coruna exploit kit was shipped in iOS 17.2 on December 11th, 2023," Apple said in an advisory. "This update brings that fix to devices that cannot update to the latest iOS version."

Fixes for CVE-2023-43010 were originally released by Apple in the following versions -

The latest round of fixes brings it to older versions of iOS and iPadOS -

  • iOS 15.8.7 and iPadOS 15.8.7 - iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
  • iOS 16.7.15 and iPadOS 16.7.15 - iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

What's more, iOS 15.8.7 and iPadOS 15.8.7 incorporate patches for three more vulnerabilities associated with the Coruna exploit kit -

  • CVE-2023-43000 (Originally fixed in iOS 16.6, released on July 24, 2023) - A use-after-free issue in WebKit that could lead to memory corruption when processing maliciously crafted web content.
  • CVE-2023-41974 (Originally fixed in iOS 17, released on September 18, 2023) - A use-after-free issue in the kernel that could allow an app to execute arbitrary code with kernel privileges.
  • CVE-2024-23222 (Originally fixed in iOS 17.3, released on January 22, 2024) - A type confusion issue in WebKit that could lead to arbitrary code execution when processing maliciously crafted web content.

Details of Coruna emerged earlier this month after Google said the exploit kit features 23 exploits across five chains designed to target iPhone models running iOS versions between 13.0 and 17.2.1. iVerify, which is tracking the malware framework that uses the exploit kit under the name CryptoWaters, said it has similarities to previous frameworks developed by threat actors affiliated with the U.S. government

The development comes amid speculation that Coruna was likely designed by U.S. military contractor L3Harris and that it may have been passed to Russian exploit broker Operation Zero by Peter Williams, a former general manager at the company who was sentenced to more than seven years in prison last month for selling several exploits in exchange for money.

An interesting aspect of Coruna is the use of two exploits (CVE-2023-32434 and CVE-2023-38606) that were weaponized as zero-days in a campaign dubbed Operation Triangulation targeting users in Russia in 2023. Kaspersky told The Hacker News that it's possible for any sufficiently skilled team to come up with their own exploits, given that both the flaws have publicly available implementations.

"Despite our extensive research, we are unable to attribute Operation Triangulation to any known APT group or exploit development company," Boris Larin, principal security researcher at Kaspersky GReAT, told The Hacker News in an email.

"To be precise: neither Google nor iVerify in their published research claims that Coruna reuses Triangulation's code. What they identify is that two exploits in Coruna — Photon and Gallium — target the same vulnerabilities. That's an important distinction. In our opinion, attribution cannot be based solely on the fact of exploitation of these vulnerabilities."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html