Apple its recent updates address the Coruna exploit that was revealed last week by Google and iVerify.

A few days ago, Google and iVerify published details about Corona, an exploit that combines multiple vulnerabilities to target iPhones running older versions of iOS. Specifically, the exploit exploits five full iOS exploit chains and 23 vulnerabilities affecting devices running iOS 13 through iOS 17.2.1.
See also: CISA: Critical vulnerability n8n in the KEV List
Apple has released iOS 16.7.15, iOS 15.8.7, iPadOS 16.7.15, and iPadOS 15.8.7, stating that they contain “important security fixes.” The company confirms that they are addressing kernel and WebKit vulnerabilities related to the Coruna exploit and are patching it on devices that cannot update to the latest version of iOS.
Here is the full security content for iOS 15.8.7 and iPadOS 15.8.7:
Kernel
– Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation) and iPod touch (7th generation)
– Impact: An application may be able to execute arbitrary code with kernel privileges. This fix related to the Corona exploit was released in iOS 17 on September 18, 2023. This update brings this fix to devices that cannot update to the latest version of iOS.
– Description : A use-after-free issue was addressed with improved memory management.
CVE-2023-41974: Félix Poulin-Bélanger
WebKit
– Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation) and iPod touch (7th generation)
– Impact: Processing malicious web content may lead to arbitrary code execution. This fix related to the Coruna exploit was released in iOS 17.3 on January 22, 2024. This update brings this fix to devices that cannot update to the latest version of iOS.
– Description: A type confusion was addressed with improved checks.
WebKit Bugzilla: 267134
CVE-2024-23222
See also: CISA: Ivanti EPM and Cisco SD-WAN vulnerabilities in the KEV List

WebKit
– Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation) and iPod touch (7th generation)
– Impact: Processing malicious web content may lead to memory corruption. This fix related to the Coruna exploit was released in iOS 16.6 on July 24, 2023. This update brings this fix to devices that cannot update to the latest version of iOS.
– Description : A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 255951
CVE-2023-43000: Apple
WebKit
– Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation) and iPod touch (7th generation)
– Impact: Processing malicious web content may lead to memory corruption. This fix related to the Coruna exploit was released in iOS 17.2 on December 11, 2023. This update brings this fix to devices that cannot update to the latest version of iOS.
– Description: The issue was addressed with improved memory management.
WebKit Bugzilla: 260913
CVE-2023-43010: Apple
And here is the full security content for iOS 16.7.15 and iPadOS 16.7.15:
WebKit
– Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch and iPad Pro 12.9-inch 1st generation
– Impact: Processing malicious web content may lead to memory corruption. This fix related to the Coruna exploit was released in iOS 17.2 on December 11, 2023. This update brings this fix to devices that cannot update to the latest version of iOS.
– Description: The issue was addressed with improved memory management.
WebKit Bugzilla: 260913
CVE-2023-43010: Apple
See also: Warning! Serious vulnerabilities in HPE Aruba CX switches

Coruna exploit
If you have an older device, it is very important to check if it is updated to a version that fixes security issues.
