top of page

Apple Warns iPhone Users to Update iOS Against Emerging Exploit Kits

  • Mar 20
  • 1 min read

Key Findings


* Coruna and DarkSword exploit kits target outdated iOS versions


* Apple warns users to update iOS to prevent data theft


* Exploit kits can compromise iPhones through malicious web content


* Devices running latest iOS versions are protected


* Multiple threat actors are utilizing these exploit techniques


Background


Apple has identified significant security vulnerabilities in older iOS versions that can be exploited by sophisticated web-based attack frameworks. The Coruna exploit kit, specifically discovered by Google's Threat Intelligence Group (GTIG), represents a complex set of techniques designed to compromise iPhones running iOS versions 13.0 through 17.2.1.


Exploit Kit Details


The Coruna exploit kit contains five full exploit chains comprising 23 total exploits. It uses advanced techniques like JavaScript obfuscation and device fingerprinting to target specific iOS versions. The framework can detect device types and load appropriate WebKit remote code execution (RCE) exploits.


Threat Actor Landscape


Multiple threat actors have been observed utilizing these exploit techniques, including:


* A surveillance vendor's customer


* UNC6353 (Ukrainian threat group)


* UNC6691 (Chinese financial threat actor)


These groups demonstrate how sophisticated exploit tools can be repurposed and traded in the cybersecurity underground market.


Recommended Actions


* Update iOS to the latest version


* Enable Lockdown Mode if updating is not immediately possible


* Be cautious of clicking unknown links or visiting unfamiliar websites


* Regularly check for and install iOS security updates


Technical Mitigation


Safari's Safe Browsing feature provides additional protection by blocking known malicious domains. Apple has released updates for iOS 15 through 26 to address these specific vulnerabilities.


Sources


  • https://securityaffairs.com/189716/security/apple-urges-iphone-users-to-update-as-coruna-and-darksword-exploit-kits-emerge.html

  • https://thehackernews.com/2026/03/apple-warns-older-iphones-vulnerable-to.html

  • https://macdailynews.com/2026/03/19/apple-warns-iphone-users-to-update-ios-to-thwart-hacking-campaigns/

  • https://www.bitdefender.com/en-us/blog/hotforsecurity/update-ios-protect-data-patch-coruna-darksword-exploits

Recent Posts

See All

Comments


  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page