CVE-2023-43010Patch(apple / ipados)

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-120

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Active exploitation appears in 12 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 27 mentions across 5 observed days

What's happening

  • Active exploitation reported across 12 signals
  • Exploit tool or code specified in 3 signals
  • Patch or workaround mentioned in 24 signals
  • Technical details provided in 18 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 15 mentions (2026-03-12); latest day: 2
  • 27 total mentions across 5 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafari

Deep dive

Activity timeline27 mentions / 5d
0481115Mentions · 2026-03-12: 15Mentions · 2026-03-13: 6Mentions · 2026-03-14: 3Mentions · 2026-03-16: 1Mentions · 2026-04-16: 2Exploit Tool / Code · 2026-03-12: 2Exploit Tool / Code · 2026-03-14: 1Active Exploitation · 2026-03-12: 6Active Exploitation · 2026-03-13: 3Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-04-16: 2Patch / Workaround · 2026-03-12: 13Patch / Workaround · 2026-03-13: 5Patch / Workaround · 2026-03-14: 3Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-04-16: 2Technical Details · 2026-03-12: 10Technical Details · 2026-03-13: 4Technical Details · 2026-03-14: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-16: 203-1203-1303-1403-1604-16
Signal classification3 categories
Patch
2488.9%
Disclosure
27.4%
General
13.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-1215
Disclosure2Patch13
2026-03-136
General1Patch5
2026-03-143
Patch3
2026-03-161
Patch1
2026-04-162
Patch2
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    ⚡ Apple backports CVE-2023-43010 fix after the WebKit flaw was used in the Coruna #iPhone exploit kit. It allows memory corruption via malicious web content. Fix now covers iOS 15.8.7 & 16.7.15 devices, including iPhone 6s, 7, 8 & X. 🔗 Read → https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html

    Post summary

    Apple has backported a fix for CVE‑2023‑43010, which was actively exploited in the Coruna iPhone exploit kit, and the update now protects iOS 15.8.7 and 16.7.15 devices.

    332264139.6K
    1.1M followersView on X
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    🔍 Attention, security professionals! New critical CVEs require immediate action: CVE-2026-20963 (SharePoint) – RCE via deserialization CVE-2025-48827 (vBulletin) – CVSS 10.0, actively exploited CVE-2025-70401/70400 (UniFi) – Path traversal and RCE with network access CVE-2023-43010 (Apple) – Memory corruption in Safari and iOS ✅ Stay up to date. 🛠️ Patches are now available. 🚨 Real threats, urgent response. #Cybersecurity #CVE #InfoSec #CISAKEV #PatchNow

    Post summary

    Multiple critical CVEs, including RCEs and path‑traversal flaws, are either actively exploited or pose significant threats, but vendor patches are now available for timely mitigation.

    01030122
    3.2K followersView on X
  • Dalbeir Singh@dalbeirthakur
    Patch

    🚨 Apple Security Alert Older iPhones targeted by the Coruna WebKit exploit (CVE-2023-43010). 📱 iPhone 6s, 7, SE, 8 & X affected 🔐 Update to iOS 15.8.7 or iOS 16.7.15 Always keep devices updated to stay protected. #CyberSecurity #Apple #iOS #TechNews https://t.co/TNRyy7KdFT

    Post summary

    The tweet alerts that older iPhones are vulnerable to CVE‑2023‑43010 and advises updating to the latest iOS versions for protection.

    01011132
    37 followersView on X
  • Miguel Marquez@Lk_arkngel
    Patch

    Apple ya corrigió estos fallos en iOS 17+ hace tiempo, pero ahora los backporteó a versiones antiguas que no pueden subir a iOS 26. Ejemplos clave: • CVE-2023-43010 (WebKit memory corruption) • Use-after-free en kernel
Dispositivos compatibles: iPhone 6s/7/SE1, iPhone 8/X, iPad Air 2, mini 4, etc.

    Post summary

    Apple has fixed CVE‑2023‑43010 (a WebKit memory corruption) and a kernel use‑after‑free, and it has back‑ported these patches to older iOS versions that cannot upgrade, indicating the vulnerabilities are already mitigated.

    1002054
    1.8K followersView on X
  • سايبر دايبر@CyberDaiber
    Patch

    أصدرت شركة أبل تحديثات أمنية لاغلاق ثغرة تسمح بتلف الذاكرة عبر محتوى ويب خبيث على أجهزة أيفون و أيباد القديمة https://nvd.nist.gov/vuln/detail/CVE-2023-43010 #الأمن_السيبراني https://t.co/kUd09qlikF

    Post summary

    Apple released security updates to fix a memory‑corruption vulnerability that can be triggered by malicious web content on older iPhone and iPad devices.

    00020316
    12.5K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    Apple has backported fixes for CVE-2023-43010 to older iPhones and iPads after the WebKit flaw was linked to the Coruna exploit kit. Legacy devices remain a target. Patch now. #Cybersecurity #AppleSecurity #VulnerabilityAlert #PatchManagement https://t.co/seReHRDM1M

    Post summary

    Apple backported fixes for CVE-2023-43010 to older iPhones and iPads, noting the WebKit flaw’s link to the Coruna exploit kit and urging users to apply the patch as legacy devices remain a target.

    0002047
    250 followersView on X
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    🔍 セキュリティ専門家の皆様、注意してください! 新しい重要な CVE には即時の対応が必要です。 CVE-2026-20963 (SharePoint) – 逆シリアル化による RCE CVE-2025-48827 (vBulletin) – CVSS 10.0、積極的に悪用されています CVE-2025-70401/70400 (UniFi) – ネットワーク アクセスによるパス トラバーサルと RCE CVE-2023-43010 (Apple) – Safari および iOS でのメモリ破損 ✅ 最新情報を入手してください。 🛠️ パッチが利用可能になりました。 🚨 本当の脅威、緊急対応。 #サイバーセキュリティ #CVE #情報セキュリティ #CISAKEV #今すぐパッチ

    Post summary

    A security advisory warns of several critical CVEs, notes that some are actively exploited, and confirms that patches are now available, urging immediate action.

    0001037
    2.9K followersView on X
  • Guardian360@Guardian360nl
    Patch

    The vulnerability, tracked as CVE-2023-43010, relates to an unspecified vulnerability in WebKit that could result in memory corruption when processing maliciously crafted web content. The iPhone maker said the issue was addressed with improved handling.

    Post summary

    Apple has addressed CVE-2023-43010, a WebKit memory corruption vulnerability, by improving content handling.

    1000056
    202 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20127 2 - CVE-2023-43010 3 - CVE-2026-21385 4 - CVE-2025-68613 5 - CVE-2026-25185 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVE identifiers along with a link to a dashboard, but offers no further context or technical information.

    00010243
    1.7K followersView on X
  • Sophia Carter@VaultEdgeITMSP
    Patch

    🚨 Apple Security Alert The Coruna WebKit exploit (CVE-2023-43010) targets older iPhones. 📱 iPhone 6s, 7, SE, 8 & X 🔐 Update to iOS 15.8.7 or iOS 16.7.15 Security tip from VaultEdge IT: Keep devices updated to reduce cyber risks. #CyberSecurity #AppleSecurity #VaultEdgeIT https://t.co/bwr97Oqj5l

    Post summary

    The tweet alerts users to CVE‑2023‑43010, advising them to update older iPhone models to mitigate the risk.

    00010135
    17 followersView on X
  • kawn@kawn2020
    Patch

    #AppleUpdate #iOS #iPadOS iOS 15.8.7 および iPadOS 15.8.7 ・CVE-2023-43000 「This fix associated with the Coruna exploit was shipped in iOS 16.6 on July 24, 2023.」 ・CVE-2023-43010 「This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023.」

    Post summary

    Apple has addressed CVE-2023-43000 and CVE-2023-43010 by shipping fixes in iOS 16.6 and iOS 17.2, respectively, which resolve the Coruna exploit.

    1000060
    89 followersView on X
  • kawn@kawn2020
    Patch

    #AppleUpdate #iOS #iPadOS Apple が iOS 16.7.15 および iPadOS 16.7.15 リリース. CVE ベースで 1 件の脆弱性に対処. ・CVE-2023-43010 「This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023.」 https://x.com/kawn2020/status/2032045176185872401

    Post summary

    Apple released iOS 16.7.15 and iPadOS 16.7.15 to patch CVE‑2023‑43010; the post lacks exploit details or active exploitation claims.

    10000102
    89 followersView on X
  • Technoholic.me@technoholic_me
    Patch

    Apple patched a WebKit flaw (CVE-2023-43010) used in the Coruna exploit kit, fixing memory corruption risk on older iOS, iPadOS, & macOS Sonoma versions. Stay updated! https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html

    Post summary

    Apple released a patch for CVE‑2023‑43010, a memory corruption flaw in WebKit that was leveraged by the Coruna exploit kit.

    0000097
    163 followersView on X
  • Horst Krieger@HorstKrieger
    Patch

    The vulnerability, tracked as CVE-2023-43010, relates to an unspecified vulnerability in WebKit that could result in memory corruption when processing maliciously crafted web content. https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html

    Post summary

    The post discusses CVE-2023-43010, a memory‑corruption flaw in WebKit triggered by malicious web content, and notes that Apple has released security updates for older devices; no PoC or active exploitation is mentioned.

    0000058
    1.3K followersView on X
  • Christina Ayiotis, Esq., CRM, CIPP/E, AIGP@christinayiotis
    Patch

    "patched .. underlying vulnerabilities in iOS updates .. over .. 2 years .. fixes for users who cannot update ..latest version. Specifically, iOS and iPadOS 15.8.7 patch 4 vulnerabilities: CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010" https://www.securityweek.com/apple-updates-older-ios-versions-to-patch-coruna-exploits/

    Post summary

    Apple released a patch for iOS 15.8.7 that addresses four CVEs associated with Coruna exploits, without mentioning PoCs or active attack reports.

    00000133
    3.5K followersView on X
  • Nicolas Coolman@NicolasCoolman
    Patch

    Apple Urgent : CVE-2023-43010 Exploitée par le Kit Coruna – Mise à Jour Immédiate pour iOS Legacy ! https://zoneantimalware.com/apple-correctif-3/

    Post summary

    Apple is urging legacy iOS users to apply an immediate update for CVE-2023-43010, which is currently being exploited by the Kit Coruna exploit kit.

    0000033
    84 followersView on X
  • TechPio@techpio_team
    Patch

    🚨 Apple Security Update for Older Devices Apple released patches for older iPhones and iPads to fix a WebKit flaw (CVE-2023-43010) linked to the Coruna exploit kit. Update your devices to stay protected. 🔗 https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html #CyberSecurity #AppleSecurity #iOSUpdate https://t.co/rTU6bjNiH3

    Post summary

    Apple released security updates for older iPhones and iPads to fix the WebKit flaw CVE-2023-43010, which is linked to the Coruna exploit kit; users are advised to update to stay protected.

    0000094
    414 followersView on X
  • securityrss.ai@securityRSS
    Patch

    Apple has released security updates for older iOS and iPadOS versions to address CVE-2023-43010, a WebKit vulnerability exploited by the Coruna exploit kit. The updates include fixes for iOS 15.8.7 and iPadOS 15.8. https://thehackernews.com/2026/03/apple-issues-security-updates-for-older.html

    Post summary

    Apple issued patches for iOS 15.8.7 and iPadOS 15.8 to fix CVE-2023-43010, a WebKit vulnerability that has been actively exploited by the Coruna exploit kit.

    00000107
    78 followersView on X
  • PostGoo@PostGoo_News
    Patch

    Apple on Wednesday backported fixes for a security flaw in iOS, iPadOS, and macOS Sonoma to older versions after it was found to be used as part of the Coruna exploit kit. The vulnerability, tracked as CVE-2023-43010, relates to an unspecified v... #News https://postgoo.com/posts/69b3a45c59f33fe74ef78618?type=article https://t.co/kYIg15T6NI

    Post summary

    Apple issued backported fixes for CVE-2023-43010 after the flaw was actively exploited as part of the Coruna exploit kit.

    0000081
    19 followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Patch

    Apple liberó actualizaciones de seguridad para versiones antiguas de iOS y iPadOS tras identificarse el uso de la vulnerabilidad CVE-2023-43010 dentro del kit de explotación Coruna, que permite corrupción de memoria al procesar contenido web malicioso. Los parches se extendieron a dispositivos que no pueden actualizar a versiones recientes del sistema e incluyen correcciones adicionales asociadas al mismo exploit kit.

    Post summary

    Apple issued security updates for legacy iOS and iPadOS devices to address CVE‑2023‑43010, a memory‑corruption flaw used by the Coruna exploit kit, and added extra fixes for the same exploitation vector.

    00000122
    3.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---

Explore more