Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1098 articles · 101864 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED
apple · ios

Coruna iPhone Hacking Toolkit Exploiting iOS Vulnerabilities

60% confidence

Description

Coruna is a sophisticated iPhone hacking toolkit that exploits 23 distinct vulnerabilities in iOS to silently install malware when a device visits a website containing exploitation code. The toolkit bypasses all iPhone defenses and is attributed to a well-resourced, likely state-sponsored group.

Affected Products

VendorProductVersions
appleios—

Related News (1 articles)

Tier C
Schneier on Security4h ago
Possible US Government iPhone Hacking Tool Leaked
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedApr 2, 2026
Last enriched4h ago
Tags
iosstate-sponsoredzero-click exploit
Trending Score39
Source articles1
Independent1
Info Completeness5/14
Missing: cve_id, versions, cvss, epss, cwe, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20700EXPKEV
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memo
Trending: 99
MEDIUMCVE-2026-28857
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lea
Trending: 14
MEDIUMCVE-2026-20691
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted
Trending: 14
MEDIUMCVE-2026-28861
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious web
Trending: 14
MEDIUMCVE-2026-28871
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website m
Trending: 14

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Apr 2, 2026
Actively Exploited
Apr 2, 2026
Exploit Available
Apr 2, 2026
Discovered by ZDM
Apr 2, 2026