Campaign
Exploitation Wave
Security Patch Release
Vulnerability
Coruna iPhone exploitation and Apple response
Updated 26.03.2026 13:07
Case score 63
Score breakdown
- Total
- 63
- Lead score
- 58
- Support bonus
- +5 / 20
- Scoring support
- 2
- Context members
- 2
Top contributors
- Campaign Base Coruna iPhone exploit activity with UNC6353 and UNC6691 reuse across watering-hole and lure-site delivery. base
- Campaign Adds direct exploitation context for Coruna reuse across Ukraine watering holes and fake finance/crypto sites. support
- Vulnerability Technical grounding for the WebKit memory-corruption flaw used in Coruna-linked exploitation. context
- Security Patch Release Legacy-device backport for the Coruna-linked CVE-2023-43010 WebKit flaw. context
Case score 63
Members 5
Latest activity 26.03.2026 13:07
Active exploitation
Patch available
Active exploitation
Patch available
Members 5
First seen 04.03.2026 15:28
Last seen 26.03.2026 13:07
Updated 26.03.2026 13:07
Overview
Coruna is being reused against **iPhone** users through watering-hole and lure-site delivery, with UNC6353 tied to compromised Ukrainian websites and UNC6691 tied to fake gambling and crypto pages. The kit fingerprints the device and iOS version before selecting an exploit path, and it will not run when **Lockdown Mode** or private browsing is enabled.
The activity spans five exploit chains and 23 exploits across older iOS and iPadOS versions, including **CVE-2024-23222** and older WebKit and kernel flaws such as **CVE-2023-43010**. Apple has backported fixes for legacy devices and Google has blocked identified infrastructure, but available evidence still does not quantify the full reach of compromise.
Coruna is being used to attack **iPhone** users through watering-hole and lure-site delivery, with UNC6353 tied to compromised Ukrainian websites and UNC6691 tied to fake gambling and crypto pages. The framework fingerprints the device and iOS version before selecting an exploit path, and it does not run when Lockdown Mode or private browsing is enabled. Google described the kit as a previously undocumented exploit package with five full chains and 23 exploits.
The activity includes exploitation of **CVE-2024-23222** and earlier Apple flaws including **CVE-2023-43010**, **CVE-2023-32434**, and **CVE-2023-38606**. Available evidence also ties the Coruna abuse to broader reuse of older WebKit and kernel weaknesses rather than a single bug. The reuse across espionage-style watering holes and financially motivated lure sites widens exposure beyond the original targeted use.
Apple backported the **CVE-2023-43010** fix to **iOS 15.8.7**, **iPadOS 15.8.7**, **iOS 16.7.15**, and **iPadOS 16.7.15** for older devices that could not move to newer releases. Google also added identified sites and domains to **Safe Browsing** and advised updating iOS or enabling **Lockdown Mode** where updating is not possible. Available evidence does not quantify compromise totals, and the full reach of the abuse remains unknown.