Apple released emergency security updates for older devices to block exploitation associated with the Coruna exploit chain, backporting fixes previously delivered in newer iOS branches. The updates target legacy hardware that cannot move to the latest operating systems, with reporting indicating iOS 15.8.7 and iPadOS 15.8.7 protect devices such as the iPhone 6s, iPhone 7, first-generation iPhone SE, iPad Air 2, iPad mini 4, and iPod touch 7. The attack path described for Coruna combines multiple flaws in the kernel and WebKit, enabling device compromise through malicious web content and potentially leading to arbitrary code execution with elevated privileges.
Apple’s security documentation also confirms a related backport in iOS 16.7.15 and iPadOS 16.7.15 for slightly newer but still unsupported models, including iPhone 8, iPhone 8 Plus, iPhone X, and several older iPads. That advisory ties the Coruna exploit to CVE-2023-43010, a memory corruption issue triggered by processing crafted web content, and states the fix was originally shipped in iOS 17.2 before being brought to devices unable to upgrade further. Together, the updates show Apple is extending protections against an actively weaponized exploit chain across multiple older device families rather than limiting remediation to current-generation platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On April 1, 2026, Apple made iOS 18.7.7 available to additional devices still running iOS 18 so they could receive protections against the DarkSword web-based exploit kit without upgrading to iOS 26. Apple said the DarkSword-related fixes had originally shipped in 2025 and framed the move as a response to continued risk from DarkSword and Coruna targeting outdated iPhones.
Apple started displaying critical security warnings on the lock screen and in Settings for older iPhones and iPads running unpatched software. The alerts warn that active web-based attacks using exploit kits such as Coruna and DarkSword are targeting outdated iOS and iPadOS versions and urge users to install updates or enable Lockdown Mode.
Apple warned users on older iOS versions to update against web-based attacks using exploit kits such as Coruna and DarkSword. It recommended moving eligible devices to iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, or iPadOS 16.7.15, and suggested Lockdown Mode where updates are not possible.
Google Threat Intelligence Group linked the Coruna/CryptoWaters exploit framework to targeted surveillance activity, Ukrainian watering hole attacks by UNC6353, and broader operations by Chinese financial threat actor UNC6691. This attribution was reported as part of later coverage of the exploit kit.
Apple published a security advisory for iOS 16.7.15 and iPadOS 16.7.15 addressing WebKit flaw CVE-2023-43010 on older iPhone and iPad models that cannot upgrade further. Apple said the issue could cause memory corruption when processing malicious web content and was fixed through improved memory handling.
On March 11, 2026, Apple released emergency updates iOS 15.8.7 and iPadOS 15.8.7 to protect older devices from Coruna-linked attacks. The updates backported fixes for four vulnerabilities—CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010—covering WebKit and kernel issues that could enable full device compromise.
Apple later stated that a fix tied to Coruna had previously been shipped in iOS 17.3. SC Media dates that release to January 22, 2024.
Apple says the WebKit fix for CVE-2023-43010 associated with the Coruna exploit was originally released in iOS 17.2. The advisory dates this remediation to December 11, 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcemacrumors.com
Open sourcethehackernews.com
Open sourcesupport.apple.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.