By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit
Computing

Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit

News Room
Last updated: 2026/03/12 at 6:37 AM
News Room Published 12 March 2026
Share
Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit
SHARE

Ravie LakshmananMar 12, 2026Vulnerability / Malware

Apple on Wednesday backported fixes for a security flaw in iOS, iPadOS, and macOS Sonoma to older versions after it was found to be used as part of the Coruna exploit kit.

The vulnerability, tracked as CVE-2023-43010, relates to an unspecified vulnerability in WebKit that could result in memory corruption when processing maliciously crafted web content. The iPhone maker said the issue was addressed with improved handling. 

“This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023,” Apple said in an advisory. “This update brings that fix to devices that cannot update to the latest iOS version.”

Fixes for CVE-2023-43010 were originally released by Apple in the following versions –

The latest round of fixes brings it to older versions of iOS and iPadOS –

  • iOS 15.8.7 and iPadOS 15.8.7 – iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
  • iOS 16.7.15 and iPadOS 16.7.15 – iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

What’s more, iOS 15.8.7 and iPadOS 15.8.7 incorporate patches for three more vulnerabilities associated with the Coruna exploit –

  • CVE-2023-43000 (Originally fixed in iOS 16.6, released on July 24, 2023) – A use-after-free issue in WebKit that could lead to memory corruption when processing maliciously crafted web content.
  • CVE-2023-41974 (Originally fixed in iOS 17, released on September 18, 2023) – A use-after-free issue in the kernel that could allow an app to execute arbitrary code with kernel privileges.
  • CVE-2024-23222 (Originally fixed in iOS 17.3 released on January 22, 2024) – A type confusion issue in WebKit that could lead to arbitrary code execution when processing maliciously crafted web content.

Details of Coruna emerged earlier this month after Google said the exploit kit features 23 exploits across five chains designed to target iPhone models running iOS versions between 13.0 and 17.2.1. iVerify, which is tracking the malware framework that uses the exploit kit under the name CryptoWaters, said it has similarities to previous frameworks developed by threat actors affiliated with the U.S. government

The development comes amid reports that Coruna was likely designed by U.S. military contractor L3Harris and that it may have been passed to Russian exploit broker Operation Zero by Peter Williams, a former general manager at the company who was sentenced to more than seven years in prison for selling several exploits in exchange for money.

An interesting aspect of Coruna is the use of two exploits (CVE-2023-32434 and CVE-2023-38606) that were weaponized as zero-days in a campaign dubbed Operation Triangulation targeting users in Russia in 2023. Kaspersky told The Hacker News that it’s possible for any sufficiently skilled team to come up with their own exploits, given that both the flaws have publicly available implementations.

“Despite our extensive research, we are unable to attribute Operation Triangulation to any known APT group or exploit development company,” Boris Larin, principal security researcher at Kaspersky GReAT, told The Hacker News in an email.

“To be precise: neither Google nor iVerify in their published research claims that Coruna reuses Triangulation’s code. What they identify is that two exploits in Coruna — Photon and Gallium — target the same vulnerabilities. That’s an important distinction. In our opinion, attribution cannot be based solely on the fact of exploitation of these vulnerabilities.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article AWS Launches Strands Labs for Experimental AI Agent Projects AWS Launches Strands Labs for Experimental AI Agent Projects
Next Article The iPhone Fold could catch up to Android 7.0 Nougat with this multitasking feature The iPhone Fold could catch up to Android 7.0 Nougat with this multitasking feature
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Bank glitch allowed customers to see how other users were spending their money
Bank glitch allowed customers to see how other users were spending their money
News
From Teens to Menopause: How Age and Obesity Affect Menstrual Health | HackerNoon
From Teens to Menopause: How Age and Obesity Affect Menstrual Health | HackerNoon
Computing
I challenged ChatGPT to a writing competition. Could it actually replace me?
I challenged ChatGPT to a writing competition. Could it actually replace me?
News
The MacBook Neo has its first price drop after just a few days
The MacBook Neo has its first price drop after just a few days
Gadget

You Might also Like

From Teens to Menopause: How Age and Obesity Affect Menstrual Health | HackerNoon
Computing

From Teens to Menopause: How Age and Obesity Affect Menstrual Health | HackerNoon

62 Min Read
Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload
Computing

Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload

17 Min Read
Xpeng’s G7 SUV features 2,200 TOPS in-house chip in quest for L3 autonomy · TechNode
Computing

Xpeng’s G7 SUV features 2,200 TOPS in-house chip in quest for L3 autonomy · TechNode

4 Min Read
C# OCR Libraries: The Definitive .NET Comparison for 2026 | HackerNoon
Computing

C# OCR Libraries: The Definitive .NET Comparison for 2026 | HackerNoon

69 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?