By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Tech DiffThe Tech DiffThe Tech Diff
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Reading: “iOS Vulnerabilities Exploited: Federal Attention Intensifies Amidst Mystery”
Share
Font ResizerAa
The Tech DiffThe Tech Diff
Font ResizerAa
  • Computers
  • Phones
  • Technology
  • Wearables
Search
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Follow US
  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy
© Copyright 2022. All Rights Reserved By The Tech Diff.
The Tech Diff > Blog > Technology > “iOS Vulnerabilities Exploited: Federal Attention Intensifies Amidst Mystery”
Technology

“iOS Vulnerabilities Exploited: Federal Attention Intensifies Amidst Mystery”

Admin
Last updated: March 7, 2026 9:13 pm
Admin
Share
“iOS Vulnerabilities Exploited: Federal Attention Intensifies Amidst Mystery”
SHARE

The Rise of Coruna: A New Exploit Kit Targeting iOS Devices

In recent years, cybersecurity has become paramount, especially with the proliferation of sophisticated threat actors targeting mobile devices. One notable development in this realm has been the emergence of the exploit kit known as “Coruna.” Discovered by Google researchers, this exploit kit stands out due to its usage by three distinct hacking groups.

Contents
The Rise of Coruna: A New Exploit Kit Targeting iOS DevicesThe Origins of CorunaA Deep Dive into the Coruna Exploit KitIdentified Exploits within CorunaCISA’s Response

The Origins of Coruna

Google first identified Coruna’s operation in February 2025. This came during an attack executed by a “customer of a surveillance vendor.” The crucial vulnerability exploited, tracked as CVE-2025-23222, had been patched a staggering 13 months prior to the attack. In July of the same year, a suspected Russian espionage group leveraged another exploit, CVE-2023-43000, targeting websites frequented by Ukrainian nationals. By December, a financially motivated threat actor from China utilized Coruna again, allowing Google to retrieve the entire exploit kit.

Upgrade Your Experience: E7 Active Noise Cancelling Headphones!
Headphones

Upgrade Your Experience: E7 Active Noise Cancelling Headphones!

$46.99
Buy Now
JBL Tune 770NC: Ultimate Noise Cancelling Headphones!
Headphones

JBL Tune 770NC: Ultimate Noise Cancelling Headphones!

$82.96
Buy Now
-43% TECKNET Bluetooth Trucker Headset: 50Hrs, Noise Cancelling!
Headphones

TECKNET Bluetooth Trucker Headset: 50Hrs, Noise Cancelling!

$79.99 Original price was: $79.99.$45.99Current price is: $45.99.
Buy Now
-20% WavePads by PostureUp: Ergonomic Wrist Rests for Pain Relief
Computer & Accessories

WavePads by PostureUp: Ergonomic Wrist Rests for Pain Relief

$24.99 Original price was: $24.99.$19.99Current price is: $19.99.
Buy Now

Researchers have noted, “How this proliferation occurred is unclear, but suggests an active market for ‘secondhand’ zero-day exploits.” They emphasized that various threat actors have now acquired advanced exploitation techniques that can be reutilized and modified with newly identified vulnerabilities.

A Deep Dive into the Coruna Exploit Kit

Google’s investigators managed to retrieve all obfuscated exploits, including their payloads. A notable incident involved the deployment of the debug version of the exploit kit, which inadvertently left all exploits exposed, revealing their internal codenames. It is in this analysis that the name “Coruna” emerged. In total, researchers collected several hundred samples encapsulating five full iOS exploit chains, which can target a wide range of iPhone models operating on iOS versions from 13.0 (released in September 2019) to version 17.2.1 (launched in December 2023).

Identified Exploits within Coruna

The exploit kit comprises 23 distinct vulnerabilities, each categorized by type, codename, targeted versions, fixed versions, and their respective CVE references. Below is a brief overview:


TypeCodenameTargeted versionsFixed versionsCVE
WebContent R/Wbuffout13 → 15.1.115.2CVE-2021-30952
WebContent R/Wjacurutu15.2 → 15.515.6CVE-2022-48503
WebContent R/Wbluebird15.6 → 16.1.216.2No CVE
WebContent R/Wterrorbird16.2 → 16.5.116.6CVE-2023-43000
WebContent R/Wcassowary16.6 → 17.2.116.7.5, 17.3CVE-2024-23222

CISA’s Response

The Cybersecurity and Infrastructure Security Agency (CISA) has taken note of Coruna, adding only three of the CVEs to its catalog:

  • CVE-2021-30952: Apple Multiple Products Integer Overflow or Wraparound Vulnerability
  • CVE-2023-41974: Apple iOS and iPadOS Use-After-Free Vulnerability
  • CVE-2023-43000: Apple Multiple products Use-After-Free Vulnerability

CISA is urging agencies to “apply mitigations per vendor instructions, follow applicable… guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” They further caution that, “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.”

For a deeper understanding and further details, you can read the full article here.

Image Credit: arstechnica.com

You Might Also Like

DJI Rewards $30K for Accidental Hack of 7,000 Romo Robovacs

“AI Educates Teen Boys on Navigating Love Safely”

“Countries Taking Action to Ban Children’s Access to Social Media”

Trump Secures Commitment from Data Centers for Power Financing

Roku Tackles Streaming Decision Fatigue with Engaging Trivia Game

Share This Article
Facebook Twitter Copy Link Print
Previous Article “MacBook Neo vs iPad 11: Which Budget Apple Device Wins?” “MacBook Neo vs iPad 11: Which Budget Apple Device Wins?”
Next Article “Samsung Galaxy Watch May Feature Dual Chip Design, Sources Say” “Samsung Galaxy Watch May Feature Dual Chip Design, Sources Say”
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Product categories

  • Computer & Accessories
  • Headphones
  • Laptops
  • Phones
  • Wearables

Trending Products

  • 52-in-1 Precision Screwdriver Set: Ultimate Repair Kit! 52-in-1 Precision Screwdriver Set: Ultimate Repair Kit! $9.99
  • Boost Productivity with the HP USB-C Dock G5: 11-in-1 Power! Boost Productivity with the HP USB-C Dock G5: 11-in-1 Power! $104.50 Original price was: $104.50.$98.59Current price is: $98.59.
  • Kawaii Cat Ear Monitor Cover: Cute 17”-24” Dust Protector! Kawaii Cat Ear Monitor Cover: Cute 17''-24'' Dust Protector! $13.99
  • MSI Crosshair 18 HX AI: Ultimate 240Hz Gaming Power! MSI Crosshair 18 HX AI: Ultimate 240Hz Gaming Power! $1,775.75
  • Budget-Friendly Reno9pro: 5.0″ IPS, Dual Camera & More! Budget-Friendly Reno9pro: 5.0" IPS, Dual Camera & More! $48.99

You Might also Like

“AI Won’t Replace Your Job: Four Compelling Reasons Why”
Technology

“AI Won’t Replace Your Job: Four Compelling Reasons Why”

Admin Admin 4 Min Read
Nvidia Reevaluates Ties with OpenAI and Anthropic, Sparks Confusion
Technology

Nvidia Reevaluates Ties with OpenAI and Anthropic, Sparks Confusion

Admin Admin 4 Min Read
“Downdetector and Speedtest Acquired by Accenture for .2B”
Technology

“Downdetector and Speedtest Acquired by Accenture for $1.2B”

Admin Admin 3 Min Read

About Us

At The Tech Diff, we believe technology is more than just innovation—it’s a lifestyle that shapes the way we work, connect, and explore the world. Our mission is to keep readers informed, inspired, and ahead of the curve with fresh updates, expert insights, and meaningful stories from across the digital landscape.

Useful Link

  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy

Categories

  • Computers
  • Phones
  • Technology
  • Wearables

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

The Tech DiffThe Tech Diff
Follow US
© Copyright 2022. All Rights Reserved By The Tech Diff.
Welcome Back!

Sign in to your account

Lost your password?