Coruna Exploit Kit: Google Details Years of iPhone Zero-Day Use by Hackers

by Anika Shah - Technology
0 comments

Coruna iOS Exploit Kit: A Proliferation of Spyware Capabilities

By Anika Shah

A newly identified exploit kit dubbed Coruna (as well known as CryptoWaters) is targeting Apple iPhone models running iOS versions from 13.0 to 17.2.1. Google Threat Intelligence Group (GTIG) has described the kit as “new and powerful,” featuring five complete iOS exploit chains and a total of 23 exploits. It is currently ineffective against the latest versions of iOS.

The Coruna exploit kit has circulated among multiple threat actors since February 2025, transitioning from a commercial surveillance operation to a government-backed attacker, and to a financially motivated actor operating from China by December. The method by which the kit changed hands remains unknown, but the findings suggest an active market for second-hand zero-day exploits, allowing reuse for various objectives.

The kit’s framework is “extremely well engineered,” with exploits connected naturally and combined using common utility and exploitation frameworks, according to GTIG. IVerify noted similarities between Coruna and frameworks previously developed by U.S. Government-affiliated threat actors. IVerify stated that Coruna represents “the first time that mass exploitation against iOS devices has been observed in the public.”

Exploits and Vulnerabilities

Coruna leverages 23 iOS vulnerabilities, 12 of which have assigned CVEs. All identified flaws have been patched by Apple. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added CVE-2021-30952, CVE-2023-41974, and CVE-2023-43000 to its Known Exploited Vulnerabilities (KEV) catalog following the kit’s abuse of these flaws.

Specifically, the kit utilizes:

  • CVE-2021-30952 (“buffout”): An integer overflow vulnerability fixed in iOS 15.2, potentially leading to arbitrary code execution via crafted web content.
  • CVE-2023-41974 (“Parallax”): A apply-after-free flaw patched in iOS 17, enabling arbitrary code execution with kernel privileges.
  • CVE-2023-43000 (“terrorbird”): Another use-after-free issue fixed in iOS 16.6, potentially triggering memory corruption through crafted web content.

Google first detected Coruna’s use in February 2025 by a “customer of a surveillance vendor” exploiting CVE-2025-23222, which had been patched 13 months prior. In July 2025, a “suspected Russian espionage group” exploited CVE-2023-43000 in attacks targeting Ukrainian individuals via compromised websites. By December, a “financially motivated threat actor from China” was utilizing the complete exploit kit.

Federal Civilian Executive Branch (FCEB) agencies are required to patch these vulnerabilities by March 26, 2026, as mandated by Binding Operational Directive (BOD) 22-01. Nine other CVEs previously associated with Coruna have already been added to the KEV catalog.

Related Posts

Leave a Comment