CVE-2023-32434
Known exploited · CISA KEV
CVSS 7.8 HIGH: an integer overflow was addressed with improved input validation. EPSS 52% (99th percentile).
CISA federal remediation date Jul 14 · date passed
Malware & Tooling · APT / Espionage
Kaspersky discovered the Coruna exploit kit using kernel exploits CVE-2023-32434 and CVE-2023-38606 against iOS. The exploits are updated zero‑days linked to the Operation Triangulation iOS campaign. Active distribution links let researchers collect, decrypt, and analyze the framework.
4 sources · Mar 27
Known exploited · CISA KEV
CVSS 7.8 HIGH: an integer overflow was addressed with improved input validation. EPSS 52% (99th percentile).
CISA federal remediation date Jul 14 · date passed
Known exploited · CISA KEV
CVSS 5.5 MEDIUM: this issue was addressed with improved state management. EPSS 3% (86th percentile).
CISA federal remediation date Aug 16 · date passed
SecurityWeek
Coruna iOS Exploit Kit Likely an Update to Operation Triangulation
Coruna contains the updated version of a kernel exploit used in Operation Triangulation three years ago.
originalThe Hacker News
Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in Recent Mass Attacks
Coruna reuses Triangulation kernel exploits targeting iOS 13–17.2.1 devices, expanding attacks into mass exploitation campaigns.
originalBleepingComputer
Coruna iOS exploit framework linked to Triangulation attacks
The Coruna exploit kit is an evolution of the framework used in the Operation Triangulation espionage campaign, which in 2023 targeted iPhones via zero-click iMessage exploits.
originalPart of the PlainSec briefing for 2026-03-29
Every edition of this story: Coruna Exploit Kit Recycles Triangulation iOS Zero‑Days