Apple patches older iPhones and iPads against Coruna exploits
好的,我现在需要帮用户总结一篇文章,控制在100字以内。用户已经提供了文章内容,我先快速浏览一下。 文章主要讲的是苹果发布了安全更新,修复了旧款iPhone和iPad的漏洞。这些漏洞被用于网络间谍和加密货币盗窃攻击,使用的是Coruna漏洞工具包。苹果提到这些补丁针对多个利用链,包括零日攻击,修复了内核权限提升和远程代码执行的问题。 漏洞列表包括四个CVE编号,涉及WebKit和内存管理问题。受影响的设备型号很多,从iPhone 6s到iPad Pro等旧款设备。此外,Coruna工具包自2025年2月以来被多个威胁组织使用,包括俄罗斯支持的黑客和中国威胁行为者。 CISA将其中三个漏洞加入已知被利用的漏洞目录,并要求联邦机构在3月26日前修复设备。苹果还提到今年初修复了一个零日漏洞。 现在需要将这些信息浓缩到100字以内。重点包括苹果发布安全更新、修复旧设备、针对Coruna工具包的漏洞、涉及内核权限和远程执行问题、影响多款设备、CISA的行动以及零日漏洞的修复。 可能的结构:苹果发布安全更新修复旧iPhone/iPad漏洞,针对Coruna工具包攻击;补丁解决内核权限提升和远程代码执行问题;影响多款设备;CISA要求修复;同时修复年初零日漏洞。 检查字数是否在100字以内,并确保信息准确完整。 </think> Apple发布安全更新修复旧款iPhone和iPad的漏洞,针对利用Coruna工具包进行网络间谍和加密货币盗窃攻击的行为。补丁解决了多个零日攻击链,涉及内核权限提升和远程代码执行问题。受影响设备包括iPhone 6s、7、SE等多款旧机型。CISA已将部分漏洞加入已知被利用目录,并要求联邦机构在3月26日前完成修复。此外,Apple还修复了年初发现的一个零日漏洞。 2026-3-12 13:45:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:4 收藏

Apple

​Apple has released security updates to patch older iPhones and iPads against a set of vulnerabilities targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit.

Some of these security flaws have already been addressed in earlier updates for newer iOS device models, starting in September 2023.

"This fix associated with the Coruna exploit," Apple said in security advisories released on Wednesday. "This update brings that fix to devices that cannot update to the latest iOS version,"

Apple said the patches will fix iOS security issues targeted by multiple exploit chains, many used in zero-day attacks aiming to help attackers escalate permissions to Kernel privileges or gain remote code execution on vulnerable devices.

The list of vulnerabilities addressed by these backported security patches includes:

  • CVE-2023-41974: A Kernel use-after-free issue addressed with improved memory management
  • CVE-2024-23222: A WekKit type confusion issue addressed with improved checks
  • CVE-2023-43000: A WebKit use-after-free issue addressed with improved memory management
  • CVE-2023-43010: A WebKit issue was addressed with improved memory handling

The list of devices impacted by these vulnerabilities is also quite extensive, as it includes a wide range of older models running iOS 15.8.7/16.7.15 and iPadOS 15.8.7/16.7.15:

  • iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPhone 8, iPhone 8 Plus, iPhone X
  • iPad Air 2, iPad mini (4th generation), iPod touch (7th generation), iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

As Google Threat Intelligence Group (GTIG) researchers previously revealed, the Coruna exploit kit has been used by multiple threat groups since February 2025, including a suspected Russian state-backed hacking group (UNC6353), a surveillance vendor customer, and a financially motivated Chinese threat actor (UNC6691).

UNC6691 was spotted deploying the exploit kit on fake gambling and crypto websites to deliver malware payloads that stole cryptocurrency wallets from infected victims' devices.

Coruna attacks timeline
Coruna attacks timeline (GTIG)

​CISA added three of the 23 vulnerabilities targeted by Coruna to its catalog of Known Exploited Vulnerabilities on Friday, including the CVE-2023-43010 WebKit flaw, which Apple backported this week.

The U.S. cybersecurity agency also ordered Federal Civilian Executive Branch (FCEB) agencies to patch their iOS devices by March 26, as mandated by the Binding Operational Directive (BOD) 22-01.

"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable," CISA warned. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise."

Since the start of the year, Apple has also fixed a zero-day vulnerability (CVE-2026-20700) exploited in an "extremely sophisticated attack" targeting specific individuals and allowing threat actors to execute arbitrary code on compromised devices.

Apple said that Google's Threat Analysis Group reported the zero-day, but didn't provide any details about how the vulnerability was exploited.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/apple/apple-patches-older-iphones-and-ipads-against-coruna-exploits/
如有侵权请联系:admin#unsafe.sh