Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageResearch Desk
Research

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

GTIG's disclosure of the Coruna iOS exploit kit — covering five exploits against iOS 13 through 17.2.1 — underscores the commercial exploit market's ability to stockpile and chain zero-days across multiple iOS generations.

Summary written by editorial AI · Source link below

Filed by Google Threat Intel1 min readRead at source ↗

Introduction Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023) . The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public expl

Editorial Analysis

Why it matters

The breadth of iOS versions covered by a single exploit kit signals that organisations with heterogeneous mobile fleets face elevated risk from commercial spyware vendors.

What to do

Enforce minimum iOS version policies via MDM and accelerate device refresh cycles to reduce exposure to exploit kits targeting legacy iOS releases.

Board brief

Commercial exploit kits covering four years of iPhone models highlight the importance of aggressive mobile patching and device lifecycle management.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Google Threat Intel

External link — opens at Google Threat Intel in a new tab.

§
Continue with

More from the Research Desk