Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload

AI advances in astronomy through UK-South African project

UK breaks down barriers and empowers women in tech

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Apple issues security update for older iOS devices targeted by Coruna WebKit exploit
Identity

Apple issues security update for older iOS devices targeted by Coruna WebKit exploit

userBy userMarch 12, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 12, 2026Vulnerabilities/Malware

Coruna WebKit exploit

Apple on Wednesday backported a fix to an older version of iOS, iPadOS, and macOS Sonoma after a security flaw was discovered to be used as part of the Coruna exploit kit.

The vulnerability, tracked as CVE-2023-43010, is related to an unspecified vulnerability in WebKit that could lead to memory corruption when processing maliciously crafted web content. The iPhone maker said the issue was resolved through improved handling.

“This fix related to the Coruna exploit shipped in iOS 17.2 on December 11, 2023,” Apple said in an advisory. “This update applies a fix to devices that cannot be updated to the latest iOS version.”

A fix for CVE-2023-43010 was originally released by Apple in the following versions:

The latest round of fixes applies this issue to older versions of iOS and iPadOS.

iOS 15.8.7 and iPadOS 15.8.7 – iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) iOS 16.7.15 and iPadOS 16.7.15 – iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7 inch, and iPad Pro 12.9 inch 1st generation

In addition, iOS 15.8.7 and iPadOS 15.8.7 include patches for three more vulnerabilities related to the Coruna exploit.

CVE-2023-43000 (originally fixed in iOS 16.6 released on July 24, 2023) – Use-after-free issue in WebKit. It may lead to memory corruption when processing maliciously crafted web content. CVE-2023-41974 (Originally fixed in iOS 17, released September 18, 2023) – A use-after-free issue in the kernel could allow an app to execute arbitrary code with kernel privileges. CVE-2024-23222 (Originally fixed in iOS 17.3 released on January 22, 2024) – WebKit type confusion issue. Processing maliciously crafted web content may lead to arbitrary code execution.

Details about Coruna were revealed earlier this month after Google announced that the exploit kit contains 23 exploits across five chains designed to target iPhone models running iOS versions 13.0 to 17.2.1. iVerify, which tracks a malware framework that uses exploit kits under the name CryptoWaters, said the framework has similarities to previous frameworks developed by threat actors affiliated with the U.S. government.

The development comes amid reports that Coruna was likely designed by US military contractor L3Harris and may have been passed on to Russian exploit broker Operation Zero by the company’s former general manager Peter Williams, who was sentenced to more than seven years in prison for selling several exploits in exchange for money.

An interesting aspect of Coruna is the use of two exploits (CVE-2023-32434 and CVE-2023-38606) that were weaponized as zero-days in a campaign called “Operation Triangulation” that targeted Russian users in 2023. Kaspersky told The Hacker News that since implementations of both flaws are publicly available, any sufficiently skilled team could come up with their own exploits.

“Despite extensive investigation, the cause of Operation Triangulation cannot be attributed to any known APT group or exploit developer,” Boris Larin, Kaspersky GReAT’s lead security researcher, told The Hacker News via email.

“To be precise, neither Google nor iVerify claim in their published research that Coruna reuses code from Triangulation. What they do identify is that two of Coruna’s exploits (Photon and Gallium) target the same vulnerability. This is an important distinction. In our opinion, attribution is not based solely on the fact of exploitation of these vulnerabilities.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEU gives green light to EUR 260 million investment in Belgium carbon capture and storage project
Next Article UK breaks down barriers and empowers women in tech
user
  • Website

Related Posts

Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload

March 12, 2026

Six Android malware families target Pix payments, banking apps, and crypto wallets

March 12, 2026

CISA reports active exploitation of n8n RCE bug as 24,700 instances remain exposed

March 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload

AI advances in astronomy through UK-South African project

UK breaks down barriers and empowers women in tech

Apple issues security update for older iOS devices targeted by Coruna WebKit exploit

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.