Vulnerabilities · 49 days ago

Coruna and DarkSword Go Mass-Market

Coruna and DarkSword, two iOS exploit chains once tied to higher-end operations, are now turning up on about 17,000 domains, according to iVerify. Researchers say the chains have kept spreading months after public disclosure and are no longer staying in nation-state hands.

The key shift is reuse: attackers do not need to build a fresh iPhone break when a working chain can be cloned onto copycat domains and tweaked. iVerify says some variants now mix techniques from both frameworks, with stronger anti-analysis, new persistence, and implants aimed at Telegram and other follow-on abuse, which makes credential and wallet theft easier to industrialize.

If your users depend on iPhones for executive access, crypto custody, or approval flows, this moves the risk from rare surveillance tooling to a broader phishing-and-exploit campaign that can be aimed at the same high-value accounts again and again.

CVE-2025-14174

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 22% (98th percentile).

CISA federal remediation date Jan 2 · date passed

CVE-2025-43529

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: a use-after-free issue was addressed with improved memory management. EPSS 9% (95th percentile).

CISA federal remediation date Jan 5 · date passed

CVE-2026-20700

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: a memory corruption issue was addressed with improved state management. EPSS 1% (70th percentile).

CISA federal remediation date Mar 5 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-08-10

Editions

Related stories