Google reveals Coruna exploit kit for iOS: 23 exploits and five chains for older iPhones
The technical value of the Coruna framework lies primarily in its architecture. According to Google, the individual exploits are connected via shared tools and modules, which allows attackers to flexibly combine different exploitation techniques.

Security researchers at Google described a new sophisticated exploit kit targeting Apple iPhone devices. The framework referred to as Coruna (also CryptoWaters) contains, according to the analysis, 23 exploits and five complete exploit chains that enable compromising devices running iOS 13.0 to iOS 17.2.1.
The existence of the tool was flagged by Google Threat Intelligence Group (GTIG). According to the researchers, it is an exceptionally complex iOS exploit framework that was observed in several different campaigns during 2025.
Importantly, most of the vulnerabilities being exploited have already been fixed in newer iOS versions, so devices with an up-to-date system are not vulnerable to the known exploits from this framework.
Exploit framework with modular architecture
The technical value of the Coruna framework lies primarily in its architecture. According to Google, the individual exploits are connected via shared tools and modules, which allows attackers to flexibly combine different exploitation techniques.
After visiting a compromised page, the JavaScript framework first performs device fingerprinting. It determines, for example:
- the exact iPhone model
- the precise iOS version
- other device parameters
Based on this information it then loads the corresponding exploit for WebKit, the rendering engine used by Safari and other apps on iOS. After successful code execution, a bypass of the Pointer Authentication Code (PAC) protection, which is meant to prevent such attacks, can also be used.
One of the key vulnerabilities exploited in these attacks is, for example, CVE-2024-23222, a type of confusion bug in the WebKit component. Apple fixed this bug in January 2024 in the updates iOS 17.3 and iPadOS 17.3, as well as in iOS 16.7.5 and iPadOS 16.7.5 for older supported devices.
Exploits circulated among different actors
Google's analysis shows that the Coruna exploit kit appeared in the hands of several different actors during 2025.
According to the researchers' findings, it was initially used by a customer of a commercial surveillance company. Later it was observed in an operation attributed to a state-sponsored group and subsequently in a campaign by a financially motivated attacker operating from China.
It is not, however, known exactly how the exploit kit moved between the different actors. According to Google, this case suggests the existence of a secondary market for exploits, where once-developed exploitation techniques can be further shared or sold.
In a related analysis, iVerify noted that Coruna represents a prominent example of how technology originally developed for sophisticated spyware can gradually make its way into the broader cybercriminal ecosystem.
Attacks via compromised websites
One of the campaigns was observed in July 2025, when the exploit framework was detected on the domain cdn.uacounter[.]com. This code was loaded as a hidden iFrame on compromised websites.
These included sites focused on:
- industrial equipment
- business tools
- local services
- e-commerce
According to Google, this activity is associated with a group labeled UNC6353, which researchers consider a likely Russian espionage operation.
In this case the framework was delivered only to selected iPhone users from specific geographic areas.
The exploits used included, for example:
- CVE-2024-23222
- CVE-2022-48503
- CVE-2023-43000
The last of these is a use-after-free vulnerability in the WebKit component, which Apple fixed in iOS 16.6.
Fake Chinese websites and wider deployment of the attack
Another campaign was observed in December 2025. The researchers discovered a large number of fake websites, mostly related to financial services.
These sites convinced users to open them from an iPhone or iPad "for a better user experience." After loading the page a hidden iFrame was injected into the browser, which downloaded the Coruna exploit kit.
Unlike the previous campaign, here there was no geolocation restriction, which suggests an attempt at a wider deployment of the attack.
The activity is attributed to a group designated UNC6691.
Malware targeting cryptocurrency wallets
After a successful exploit, a loader named PlasmaLoader (PLASMAGRID) was installed on the device.
This component subsequently downloaded additional modules from the attackers' command-and-control servers and enabled, for example:
- theft of cryptocurrency wallets
- extraction of sensitive data from apps
- remotely launching additional malicious code
Targeted apps included, for example:
- Base
- Bitget Wallet
- Exodus
- MetaMask
The malware also included a Domain Generation Algorithm (DGA) that generated fallback domains with the .xyz TLD in case the primary command-and-control infrastructure was not available.
A total of 23 exploits for different iOS versions
In the debug version of the exploit kit researchers found five complete exploit chains and a total of 23 exploits that cover a wide range of iOS versions.
For example:
- Neutron – CVE-2020-27932 (iOS 13)
- buffout – CVE-2021-30952 (iOS 13 to 15.1.1)
- jacurutu – CVE-2022-48503 (iOS 15.2 to 15.5)
- Parallax – CVE-2023-41974 (iOS 16.4 to 16.7)
- cassowary – CVE-2024-23222 (iOS 16.6 to 17.2.1)
According to Google, some of these exploits were also used in past state operations, for example in the campaign known as Operation Triangulation.
CISA added vulnerabilities to the KEV catalog
The U.S. agency CISA responded to the findings on March 5, 2026 by adding several of the exploited vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog.
Specifically, these are:
- CVE-2021-30952
- CVE-2023-41974
- CVE-2023-43000
U.S. federal agencies must remediate these flaws no later than March 26, 2026.
How to protect yourself
The Coruna exploit kit primarily targets older or unpatched iOS versions. Basic protection is therefore keeping the system regularly updated.
Security experts especially recommend:
- keeping iOS up to date
- enabling Lockdown Mode for high-risk users
- avoiding suspicious websites
- using an up-to-date version of Safari
Interestingly, the exploit framework automatically terminates the attack on devices with active Lockdown Mode or when using private browsing, which suggests attackers take these protective mechanisms into account.
A shift in mobile cyberattacks
According to security researchers, the Coruna case shows a broader trend in mobile security. Sophisticated exploits that were previously reserved mainly for narrowly targeted espionage operations can gradually end up in the hands of a wider range of actors.
This increases the risk that similar attacks may appear more frequently in the future outside of highly targeted operations.