2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Apple pushes lock‑screen warnings to outdated iPhones amid active web exploit activity


Apple has started delivering lock-screen notifications to users of iPhones and iPads that are running older releases of iOS and iPadOS, warning them about live web-based attacks and urging an immediate software update.

The action was first reported by MacRumors, which said affected devices are receiving a prominent alert telling owners their devices are running outdated software and recommending installing the critical patch to stay protected.

The alerts arrive roughly a week after Apple published a support document telling people on legacy iOS and iPadOS builds to update after researchers uncovered new web exploit toolkits such as Coruna and DarkSword. Security teams have observed multiple, differently motivated threat actors using those kits over the last year to drop malicious payloads when victims visit compromised websites.

According to published analyses, Coruna is aimed at devices running iOS versions 13.0 through 17.2.1, while DarkSword is crafted to affect iPhones on iOS versions 18.4 through 18.7.

A fresh report from Kaspersky this week argues that the Coruna kit represents a continued, actively maintained evolution of the toolkit behind Operation Triangulation - a complex campaign that exploited zero-click iMessage vulnerabilities and first surfaced in June 2023.

Kaspersky emphasizes that Coruna is not merely a collection of public, one-off flaws; instead, it appears to be an ongoing refinement of the earlier Operation Triangulation framework.

Researchers have not yet determined how these exploit frameworks became available to multiple threat actors, but recent work raises the possibility of a secondary market for previously private zero-day vulnerabilities that enables resale and wider misuse.

The availability of these toolkits, and the leak of a newer DarkSword variant, has sparked concern that such capabilities could spread beyond state actors and be used broadly by criminals - effectively lowering the barrier to mass exploitation and expanding the attack surface for iPhones and iPads.

For users who cannot upgrade to a supported iOS or iPadOS release, Apple recommends enabling Lockdown Mode where supported; the feature, introduced in 2022, is present on devices running iOS 16 and later and is designed to add protections against hostile web content.

In comments provided to TechCrunch, Apple said it is not aware of any successful mercenary spyware intrusions against devices with Lockdown Mode enabled, underscoring the company’s position that the defensive feature remains effective against known attempts to weaponize these web exploits.

First published on March 27, 2026.
Last updated on April 24, 2026.