Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks
Apple is urging owners of older iPhones to install updates after researchers linked web-based exploit kits called Coruna and DarkSword to active attacks that abuse outdated iOS releases. The company says malicious websites and links are being used to deliver exploit chains that can ultimately siphon sensitive information from affected devices.
In guidance published on its support pages, Apple warned that interacting with a malicious link or browsing a compromised site on an unsupported iOS build could put the data on the device at risk. The vendor said it investigated the issues as they surfaced and pushed fixes rapidly for the most recent operating system releases to help disrupt these offensive campaigns.
Devices already running the latest iPhone software do not require additional action, Apple added. According to the advisory, protections are included in iOS builds spanning versions 15 through 26, which contain patches for the flaws exploited by these kits.
For those on older hardware or older software, Apple outlined several specific steps to reduce exposure:
• Update legacy devices that cannot move to the newest iOS to iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, or iPadOS 16.7.15.
• For handsets still on iOS 13 or iOS 14, upgrade to iOS 15 to receive the latest protections; Apple said a Critical Security Update for these users is expected to be distributed in the “next few days.”
• If updating is not possible, consider enabling Lockdown Mode (when available) to shrink the device’s attack surface and limit exposure to malicious web content and related threats.
Apple emphasized that keeping software current remains the most effective single measure to secure Apple devices, noting that endpoints running updated builds were not susceptible to the reported attacks.
The advisory follows evidence that two separate iOS exploits have been weaponized by multiple malicious actors-of different motives-using watering-hole compromises to deliver the exploit kits. Security firm iVerify observed that vulnerabilities once used selectively in state-sponsored mobile spyware operations are now being repurposed for broader, mass-targeting campaigns.