
Apple released new security updates yesterday for iOS/iPad OS 15 and 16 to address the Coruna exploit targeting iOS versions 13 to 17. The software updates come a little more than a week after the Google Threat Intelligence Group shared more details about the security exploit, which has been used by a customer of a surveillance company, fake Chinese gambling and Crypto websites, and more.
iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, and iPadOS 16.7.15 are now available to protect iPhone and iPad users running these older versions of the platforms from these critical vulnerabilities. One of these vulnerabilities, CVE-2024-23222, targets Apple’s WebKit engine, and it may lead to arbitrary code execution after processing maliciously crafted web content. It has been fixed in iOS and iPadOS 17.3, released on January 22, 2024, but older versions of the platform were still vulnerable.
Apple also fixed a kernel vulnerability (CVE-2023-41974) in iOS 15.8.7 and iPadOS 15.8.7 that apps could use to execute arbitrary code with kernel privileges. This vulnerability had already been fixed on iOS and iPadOS 17, released on September 18, 2023.
You can read more details about the content of Apple’s security updates on the company’s website. You should install the updates asap if you’re still using an iPhone 6s, iPhone 7, iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation).