Apple iOS outdated-device exploit-kit mitigation advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Apple is sending Lock Screen notifications to outdated iPhones and iPads after detecting active web-based attacks, urging users to install updates. The latest notice says Apple is aware of attacks targeting out-of-date iOS software on affected devices, and it follows the company’s earlier guidance about the Coruna and DarkSword exploit kits. Users who cannot update to a supported version are advised to enable Lockdown Mode on iOS 16 and later to reduce exposure to malicious web content.
Related Happenings
IOS 26.5 beta rolls out default end-to-end encrypted RCS messaging on iPhone and Android
Security Tool/Service
First: 12.05.2026 08:18
Last: 12.05.2026 08:18
Sources 1
About this happening:
Apple's **iOS 26.5** beta adds **default end-to-end encrypted RCS** messaging for **iPhone** and **Android** users, strengthening privacy in cross-platform chats. The rollout cove...
IOS 26.5 beta rolls out default end-to-end encrypted RCS messaging on iPhone and Android
Security Tool/ServiceAbout this happening: Apple's **iOS 26.5** beta adds **default end-to-end encrypted RCS** messaging for **iPhone** and **Android** users, strengthening privacy in cross-platform chats. The rollout cove...
Apple out-of-band iOS/iPadOS security updates (CVE-2026-28950)
Security Patch Release
First: 22.04.2026 23:58
Last: 22.04.2026 23:58
Sources 1
About this happening:
**Apple** released **out-of-band security updates** for **iPhone and iPad** on **April 22, 2026** to fix **CVE-2026-28950**. The patch addresses a **Notification Services** flaw t...
Apple out-of-band iOS/iPadOS security updates (CVE-2026-28950)
Security Patch ReleaseAbout this happening: **Apple** released **out-of-band security updates** for **iPhone and iPad** on **April 22, 2026** to fix **CVE-2026-28950**. The patch addresses a **Notification Services** flaw t...
Latest development: 23.04.2026 11:50
Apple issued **iOS 26.4.2**, **iPadOS 26.4.2**, **iOS 18.7.8**, and **iPadOS 18.7.8** on **2026-04-23** to close **CVE-2026-28950**, which could preserve deleted-message notifications on affected devices.
Apple Notification Services notification retention flaw (CVE-2026-28950)
Vulnerability
First: 22.04.2026 23:58
Last: 22.04.2026 23:58
Sources 1
About this happening:
**Apple** released **out-of-band updates** for **iPhone and iPad** to fix **CVE-2026-28950**, a **Notification Services** flaw that could let deleted notifications remain stored o...
Apple Notification Services notification retention flaw (CVE-2026-28950)
VulnerabilityAbout this happening: **Apple** released **out-of-band updates** for **iPhone and iPad** to fix **CVE-2026-28950**, a **Notification Services** flaw that could let deleted notifications remain stored o...
Latest development: 23.04.2026 11:50
Apple released iOS 26.4.2, iPadOS 26.4.2, iOS 18.7.8, and iPadOS 18.7.8 to address CVE-2026-28950, a logging flaw that could retain notifications marked for deletion on the device. The update improves data redaction so inadvertently preserved notifications are removed, and reporting also links the flaw to recovered Signal chats in the Prairieland case involving law enforcement and the FBI.
Apple iOS 18.7.7 security update expansion for DarkSword
Security Patch Release
First: 02.04.2026 00:50
Last: 02.04.2026 00:50
Sources 1
About this happening:
Apple expanded **iOS 18.7.7** availability to more older **iPhones and iPads** on **April 1, 2026**, letting devices that stay on **iOS 18** receive protections against the **acti...
Apple iOS 18.7.7 security update expansion for DarkSword
Security Patch ReleaseAbout this happening: Apple expanded **iOS 18.7.7** availability to more older **iPhones and iPads** on **April 1, 2026**, letting devices that stay on **iOS 18** receive protections against the **acti...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical Analysis
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
**Coruna** has been linked to an **updated** exploit lineage from **Operation Triangulation**, showing that a long-running iPhone attack framework continues to evolve and can stil...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical AnalysisAbout this happening: **Coruna** has been linked to an **updated** exploit lineage from **Operation Triangulation**, showing that a long-running iPhone attack framework continues to evolve and can stil...
Timeline
-
20.03.2026 07:16 3 articles · 2mo ago
Apple warns older iPhone and iPad users about Coruna and DarkSword
Initial DisclosureApple warned that older iPhones and iPads running outdated iOS can be exposed to web-based attacks using the Coruna and DarkSword exploit kits, where malicious web content on compromised websites can trigger an infection chain and steal sensitive data. Apple recommended updating to iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, or iPadOS 16.7.15 for older devices, moving devices on iOS 13 or iOS 14 to iOS 15, and enabling Lockdown Mode when updating is not possible.
Show sources
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22