The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Google says it found a powerful iPhone exploit kit it named Coruna in three kinds of campaigns during 2025. The kit contained five complete iOS exploit chains with 23 exploits and targeted devices running iOS 13.0 through iOS 17.2.1. A March 2026 report from Google Threat Intelligence Group (GTIG) does not give an exact number of victims; “thousands” comes from the headline and coverage of TechRepublic’s March 5, 2026 article, not a quantified total in Google’s report.
What is Coruna, and what did Google find?
Coruna is the name GTIG gave to an iOS exploit kit: a collection of exploits and supporting code designed to break through multiple layers of iPhone security. In its March 3, 2026 technical report, Google described five full iOS exploit chains containing 23 exploits. The kit was built for iPhone models running iOS 13.0, released in September 2019, through iOS 17.2.1, released in December 2023.
That range identifies the software versions the kit targeted; it does not establish how many devices were exposed, successfully exploited, or had information taken. Google’s report gives no exact victim count. The word “thousands” appears in TechRepublic’s headline and article, but should not be mistaken for a precise figure published by Google.
How was Coruna used in the 2025 campaigns?
GTIG reported seeing the same framework in three different settings. The observations show a shift from a surveillance-vendor customer’s operation to espionage-linked watering-hole activity and then broader financially motivated campaigns. Google said the mechanism by which Coruna proliferated remained unclear.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| When and setting | What GTIG observed | Attribution and limits |
|---|---|---|
| February 2025: surveillance operation | Google captured parts of an exploit chain used by a customer of a surveillance company. | GTIG described the customer’s use; the report does not establish that the customer built the kit. |
| Summer 2025: Ukrainian websites | The framework appeared on compromised Ukrainian websites. A hidden iframe delivered it only to selected iPhone users in a specific geographic area. | GTIG attributed the watering-hole attacks to suspected Russian espionage group UNC6353. Google said it worked with CERT-UA to clean up the sites. |
| Later in 2025: fake Chinese websites | Google recovered the full kit across a large set of fake Chinese websites, mostly related to finance. The sites tried to persuade visitors to use iOS devices; delivery did not depend on visitor geolocation. | GTIG linked these campaigns to financially motivated actor UNC6691. |
These are Google’s observations and attributions, not proof that every visitor to a compromised or fake site was infected. The later campaign also means suspicious links were not the only relevant risk: the reported delivery included compromised websites and pages designed to attract iPhone users.
How did the exploit chain work?
According to GTIG’s analysis of recovered code, Coruna first fingerprinted an iPhone and selected a WebKit remote-code-execution exploit compatible with that device. It then used a pointer authentication code (PAC) bypass and proceeded through a loader and additional exploit stages. The report’s exploit table groups techniques across WebKit read/write, PAC bypass, sandbox escape, privilege escalation, and Page Protection Layer bypass.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Google identified a WebKit exploit associated with CVE-2024-23222 in a device running iOS 17.2; Apple fixed that vulnerability in iOS 17.3 on January 22, 2024. GTIG cautioned that its exploit and CVE analysis was ongoing and that some associations could be revised. The report does not establish that every exploit in the kit was a zero-day during every campaign.
Did Coruna steal cryptocurrency or financial information?
Recovered final modules were designed to search for financial and cryptocurrency information. GTIG described capabilities including looking for QR codes and text such as backup phrases in Apple Memos. That establishes what the analyzed samples could seek; it does not show that a particular user’s wallet, account, or funds were accessed or stolen.
Rank #3
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How can iPhone users reduce the risk?
Install the latest iOS version your iPhone supports
Update the device using the newest iOS release available for that model. GTIG says Coruna is not effective against the latest iOS version and strongly urges users to update. Because Coruna targeted versions through iOS 17.2.1, running an older release within that range is a reason to prioritize an update if one is available.
Enable Lockdown Mode if you cannot update
If an update is not possible, Google recommends Apple’s Lockdown Mode. GTIG’s technical report says Coruna stops when Lockdown Mode is enabled. It is a protective option for people who cannot bring a device up to date, not a substitute for installing supported security updates when available.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For organizations managing iPhones
TechRepublic’s coverage suggests operational steps for managed fleets. These are recommendations, not guarantees that an organization will prevent compromise:
- Use mobile device management (MDM) to enforce automatic patching where appropriate.
- Consider Lockdown Mode for users with elevated risk.
- Integrate mobile threat defense with MDM, and monitor for suspicious domains and HTTP headers.
Google also said it added identified websites and domains to Safe Browsing. That does not remove the need to patch devices or guarantee that every malicious page will be blocked.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsQuick Recap
Best Value
- 【Powerful 130dB Self Defense Emergency Alarm】This personal alarm emits a 130dB ultra-loud siren that can be heard up to 600 feet away, effectively scaring off attackers and drawing attention from people nearby. Ideal for women, kids, elderly, night runners, and anyone walking alone—an essential safety keychain for daily protection.
- 【USB-C Rechargeable & Long-Lasting Performance】Built-in rechargeable battery supports up to 2 hours of continuous siren use and 1 year of standby time. Charging via USB-C cable (universal & fast), no need for frequent battery replacement. Low-power reminder ensures the alarm is always ready for emergencies.
- 【Portable Keychain Design for Easy Carrying】Lightweight & compact with a sturdy keychain clip, easy to attach to bags, purses, backpacks, belts, or keys. Take it anywhere—commuting, traveling, camping, school, or night walks. Discreet but powerful security on the go.
- 【LED Strobe Light & SOS Emergency Function】Equipped with a bright LED strobe light that works as a flashlight for night use and an SOS emergency signal in danger. One-button control for quick activation: pull the pin to trigger alarm + strobe light, maximize your safety in dark or emergency situations.
- 【4-Pack Value Set & Wide Application】Package includes 4 personal alarms (Aqua/Black/Pink/White) + 4 keychains. Perfect for family, friends, and daily sharing. FCC/CE certified, safe and reliable. If the alarm sounds weak, simply recharge it via USB-C for full power again.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

