Apple Releases Emergency iOS 15.8.7 Update to Block ‘Coruna’ Exploit Kit
## Security Update: iOS 15.8.7 and iPadOS 15.8.7 Released
Security Update: iOS 15.8.7 and iPadOS 15.8.7 Released
Apple has issued an emergency security update, iOS 15.8.7 and iPadOS 15.8.7, aimed at safeguarding older iPhones and iPads from a sophisticated threat known as the Coruna exploit kit.
Released on Sat, Mar 11, 2026, this critical patch backports several significant security fixes that were previously deployed for newer devices running iOS 16 and iOS 17.
Due to the inability of older hardware to upgrade to the latest operating systems, Apple provides occasional updates to address severe vulnerabilities.
This release addresses four specific vulnerabilities within the device’s Kernel and WebKit engine that could be exploited to execute malicious code, compromising unpatched systems.
The Coruna exploit kit exploits known memory corruption and use-after-free vulnerabilities. By targeting users with maliciously crafted web content, attackers can exploit these flaws to bypass security sandboxes. Once out of the sandbox, the exploit targets the device’s Kernel to elevate privileges, granting the attacker extensive control over the compromised device.
Due to the inability of older hardware to upgrade to the latest operating systems, Apple provides occasional updates to address severe vulnerabilities.
Apple has backported four critical fixes to the iOS 15 ecosystem. The update addresses one Kernel vulnerability and three flaws within WebKit, Apple’s browser engine. The vulnerabilities include:
CVE-2023-41974 (Kernel): A use-after-free issue allowing arbitrary code execution with maximum kernel privileges. Improved memory management mitigates this threat. CVE-2024-23222 (WebKit): A type confusion vulnerability that could lead to arbitrary code execution. Enhanced security checks have been implemented to resolve this. CVE-2023-43000 (WebKit): A use-after-free vulnerability resulting in memory corruption. Improved memory management mitigates this threat. CVE-2023-43010 (WebKit): A memory handling issue tied to malicious web content. Improved memory handling resolves this vulnerability.
This emergency update targets older Apple hardware no longer eligible for mainline iOS updates. Affected devices include:
iPhone 6s (all models). iPhone 7 (all models). iPhone SE (1st generation). iPad Air 2. iPad mini (4th generation). iPod touch (7th generation).
Users of these older devices are strongly advised to update their operating systems immediately. To install the patch, navigate to Settings, tap General, and select Software Update to download and apply iOS 15.8.7 or iPadOS 15.8.7.
Based on reporting by GBHackers.
