Apple patches Coruna exploit kit flaws for older iOS versions
嗯,用户让我总结这篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我需要快速浏览文章内容。 文章主要讲的是Google在2026年3月3日警告了一个针对苹果iPhone的恶意软件工具包,影响了从iOS13到17.2.1的版本。苹果已经修复了这些漏洞,并提到了Coruna工具包被用于定向攻击和水坑攻击,后来又被用于大量虚假金融网站。攻击利用了WebKit和内核漏洞。 接下来,我需要将这些信息浓缩到100字以内。重点包括时间、警告内容、影响范围、漏洞修复情况以及攻击方式的变化。 可能的结构是:Google警告恶意软件影响iPhone旧版本,苹果已修复漏洞,该工具包被用于定向和广泛攻击。 这样既涵盖了主要信息,又符合字数限制。 </think> Google警告称,针对苹果iPhone旧版本的操作系统(iOS 13.0至17.2.1)存在一个强大的恶意软件工具包Coruna。该工具包最初用于定向攻击,后被用于针对乌克兰用户的水坑攻击,并出现在大量虚假中文金融网站上。苹果已修复相关漏洞。 2026-3-12 17:49:44 Author: www.malwarebytes.com(查看原文) 阅读量:7 收藏

On March 3, 2026, Google warned about a powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023).

In the latest security updates, Apple patched the vulnerabilities used in the Coruna exploit kit for older mobile devices that can no longer be updated to the latest iOS version. For newer iOS versions, patches associated with the Coruna exploit were already shipped in iOS 16.6 through 17.2 in updates released in 2023 and 2024.

The Coruna exploit kit was first observed in highly targeted attacks, but was later seen in watering hole attacks targeting Ukrainian users by a suspected Russian espionage group. Later still, it appeared on a very large set of fake Chinese financial websites, suggesting the exploit was being used by more mainstream cybercriminals.

The exploit relies on WebKit vulnerabilities (CVE-2023-43000 and CVE-2024-23222) that can be triggered by processing  maliciously crafted web content, and then gains kernel privileges by abusing a separate kernel vulnerability tracked as CVE-2023-41974.

The table below shows which updates are available and points you to the relevant security content for that operating system (OS).

How to update your iPhone or iPad

For iOS and iPadOS users, here’s how to check if you’re using the latest software version:

  • Go to Settings > General > Software Update. You will see if there are updates available and be guided through installing them.
  • Turn on Automatic Updates if you haven’t already. You’ll find it on the same screen.

We don’t just report on phone security—we provide it

Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by downloading Malwarebytes for iOS, and Malwarebytes for Android today.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/news/2026/03/apple-patches-coruna-exploit-kit-flaws-for-older-ios-versions
如有侵权请联系:admin#unsafe.sh