
Google’s experts have uncovered a cluster of exploits targeting the iPhone, which has been leveraged by malicious actors for several years. This collective of tools has been dubbed “Coruna,” according to a report from the Google Cloud portal (18+).
This newly identified hacking methodology saw deployment in both surveillance operations and financially driven assaults. Analysts from Google’s Threat Intelligence Group identified five complete exploit chains and 23 distinct security flaws within the iOS operating system as part of this toolkit.
The scheme is capable of compromising devices running system versions ranging from iOS 13 up to iOS 17.2.1. Certain components of the circumvention methods had never been disclosed before, enabling them to bypass the platform’s native security measures.
In the experts’ view, the history of Coruna illustrates a gradual dissemination of sophisticated hacking capabilities across different adversarial groups. A portion of the attack infrastructure was initially intercepted in February 2025. One of the exploit chains utilized the vulnerability identified as CVE-2024-23222, which Apple patched in January 2024 with the release of the iOS 17.3 update.