CVE-2023-32434Active Exploitation(apple / ipados)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-07-14. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-190

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • watchos

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-27); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacoswatchos

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-26: 2Mentions · 2026-03-27: 3Mentions · 2026-06-28: 1PoC Mentioned / Linked · 2026-03-27: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 3Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 103-0503-2603-2706-28
Signal classification3 categories
Active Exploitation
457.1%
General
228.6%
Disclosure
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-262
Active Exploitation1General1
2026-03-273
Active Exploitation3
2026-06-281
General1
Full discourse7 posts
  • Alfie@alfiecg_dev
    General

    High quality exploitation of a high quality bug. It’s fascinating to see people still coming up with new ways to exploit CVE-2023-32434. Fantastic read!

    Post summary

    The statement praises ongoing exploitation of CVE‑2023‑32434 but provides no technical data, tools, or evidence of real‑world attacks.

    41601784529.8K
    8.7K followersView on X
  • ArmoredMobile@ArmoredMobile
    Active Exploitation

    The Coruna iOS exploit kit reuses exploits from Operation Triangulation, including CVE-2023-32434 & CVE-2023-38606. Originally used in targeted espionage, it’s now seen in broader attacks, highlighting the growing proliferation of advanced exploit tools. Read: https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/ #Coruna #Triangulation #iOS #ZeroDay @ArmoredMobile

    Post summary

    The Coruna iOS exploit kit reuses CVE-2023-32434 and CVE-2023-38606 and is now reported to be actively exploited in broader attacks.

    00030113
    62 followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    『the kernel exploit for CVE-2023-32434 and CVE-2023-38606 vulnerabilities used in Coruna, in fact, is an updated version of the same exploit that had been used in Operation Triangulation.』🧐 Coruna: the framework used in Operation Triangulation https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/

    Post summary

    The message reveals that a kernel exploit for CVE‑2023‑32434 and CVE‑2023‑38606 has been updated and deployed in the Coruna framework, having previously appeared in Operation Triangulation, indicating ongoing active exploitation.

    10000522
    6.8K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals the Coruna exploit kit has transitioned from government surveillance tool to widespread cybercriminal weapon targeting iOS devices. Attackers chain CVE-2023-32434 and CVE-2023-38606 to achieve kernel-level compromise and establish persistent C2 channels. This demonstrates how advanced exploits proliferate across threat actor groups. #ZeroDay #ThreatIntel 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/coruna-exploit-kit-2026

    Post summary

    Attackers chain CVE‑2023‑32434 and CVE‑2023‑38606 to achieve kernel‑level compromise on iOS, creating persistent C2 channels. This demonstrates that the CVEs are being actively exploited in the wild.

    00000106
    1.9K followersView on X
  • CybrPulse@CybrPulse
    Active Exploitation

    Coruna iOS kit: 23 exploits, 5 chains, nation-state code now in criminal hands. CVE-2023-32434 gives full kernel control — same vuln from 2023 Operation Triangulation spyware. First confirmed mass iOS exploitation. CISA patch deadline was today. https://thehackernews.com/2026/03/coruna-ios-kit-reuses-2023.html

    Post summary

    The post reports that CVE-2023-32434 has led to mass exploitation of iOS devices, with 23 exploit chains now in criminal use, prompting a CISA patch deadline.

    0000063
    22 followersView on X
  • Shah Sheikh@shah_sheikh
    General

    [Securelist] Coruna: the framework used in Operation Triangulation. Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the... http://ow.ly/3nj8106wnPa

    Post summary

    The snippet reports that an updated kernel exploit targeting iPhones is used for CVE‑2023‑32434 and CVE‑2023‑38606 within the Coruna exploit kit, but it offers no PoC details or evidence of active exploitation.

    0000057
    2.2K followersView on X
  • Cyberwatcher_@cyberwatcher_
    Disclosure

    Coruna : nouveau spyware iOS ciblant iOS, lié à l'Opération Triangulation. Les failles zero-day CVE-2023-32434 & CVE-2023-38606 ont été découvertes par Kaspersky. #Cybersecurity #InfoSec #Vulnerability https://www.undernews.fr/hacking-hacktivisme/espionnage-ios-coruna-les-liens-avec-loperation-triangulation-decryptes-par-kaspersky.html

    Post summary

    The article announces a new iOS spyware linked to the Triangulation operation, noting zero-day CVEs CVE-2023-32434 and CVE-2023-38606 discovered by Kaspersky, but provides no further technical or operational details.

    0000029
    12 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplewatchos---

Explore more