Feds Must Update iOS Devices Immediately to Block “Coruna” Crypto-Theft Attacks
Mar 6, 2026 // 19:54 - Niko Dunn


On March 5, 2026, the CISA (Cybersecurity and Infrastructure Security Agency) officially added three iOS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of their use in crypto-theft and cyberespionage campaigns. Federal agencies have been ordered to patch these flaws by March 26, 2026.

The “Coruna” Exploit Kit

The vulnerabilities are part of a sophisticated exploit kit dubbed Coruna, first identified by Google’s Threat Intelligence Group (GTIG) and iVerify. The kit features a “1-click” attack chain triggered when a user visits a compromised website. 

  • Targeted Flaws: The primary vulnerabilities added to the KEV include:
    • CVE-2021-30952: A memory corruption issue allowing kernel privilege escalation.
    • CVE-2023-41974: A use-after-free vulnerability in WebKit.
    • CVE-2023-43000: A flaw enabling arbitrary code execution with kernel privileges.
  • Malicious Objective: Financially motivated threat actors (tracked as UNC6691) have used the kit to target cryptocurrency traders. The malware scans for:
    • BIP39 seed phrases (mnemonic phrases) in the Notes app.
    • QR codes containing private keys in the photo library.
    • Sensitive data from wallet apps like MetaMaskand Uniswap. 

Risk and Mitigation

While the Coruna kit is highly sophisticated, it is only effective against iOS versions 13.0 through 17.2.1. It does not work on the most recent versions of iOS (v18 and later). 

  • CISA Directive: All Federal Civilian Executive Branch (FCEB) agencies must identify and patch vulnerable devices immediately to comply with Binding Operational Directive (BOD) 22-01.
  • Defensive Measures: Researchers note that the exploit is blocked if the user is in Private Browsing mode or has enabled Apple’s Lockdown Mode, as the malware performs environment checks to avoid execution in secured configurations. 

#“coruna”:  #attacks  #block  #crypto-theft  #devices  #feds  #immediately  #ios  #must  #news  #update   —   News