Why Google cybersecurity researchers are asking iPhone users to update their phones immediately as conflict in Middle East continues

Google cybersecurity researchers are urging iPhone users to update their devices to the latest version of iOS immediately. This comes after the Google Threat Intelligence Group (GTIG) discovered a dangerous exploit kit that targets a wide range of older iPhone software versions. The warning comes as geopolitical tensions, including the ongoing conflict in the Middle East, raise concerns that cyber tools may be used in targeted surveillance or espionage campaigns.

GITG researchers have recently discovered an exploit kit called Coruna that targets iPhones running iOS 13 through iOS 17.2.1. The toolkit includes multiple vulnerabilities that attackers can use to gain control of a device and extract sensitive data. According to Google, the exploit kit does not work on the latest version of iOS, which is why the company is advising users to update their devices immediately.

What Google cybersecurity researchers discovered

In a report, GITG researchers have revealed that the Coruna exploit kit contains five full exploit chains and 23 separate exploits that allow attackers to compromise different versions of iOS. Google researchers said the toolkit uses a combination of browser-based vulnerabilities and system-level exploits to gain access to a device.

The attack process typically begins when an iPhone user visits a malicious or compromised website.

A hidden script then identifies the device type and the iOS version running on it. Based on this information, the system delivers a specific exploit designed to work on that device.

Google said one of the vulnerabilities used in the attacks (CVE-2024-23222) was a zero-day before Apple fixed it in iOS 17.3. GTIG said the exploit toolkit appears to have circulated among several different threat actors over time.

Researchers first identified parts of the exploit chain in February 2025, when it was being used by a customer of a commercial surveillance vendor. Later in the year, the same toolkit was used in attacks targeting Ukrainian users, which researchers linked to a suspected Russian espionage group known as UNC6353.

By late 2025, the exploit kit was also observed in campaigns run by a financially motivated threat actor operating out of China, tracked by Google as UNC6691. In those cases, the attacks were delivered via fake financial and cryptocurrency websites designed to lure iPhone users to visit them.

Researchers said the spread of the toolkit across different groups suggests an active market for reused or resold cyber-espionage tools.

How hackers haver used this iPhone security flaw to steal financial data

As per the GITG report, once the exploit chain successfully compromised a device, it deployed a program called PlasmaLoader that enabled attackers to collect sensitive information.

According to Google’s analysis, the malware was designed to search for financial data and cryptocurrency wallet information stored on the device. It could scan notes, images, and text files for keywords such as “backup phrase” or “bank account,” and transmit the information to attacker-controlled servers.

The malware also included modules capable of extracting data from several cryptocurrency wallet apps, including MetaMask, Trust Wallet, Phantom, Exodus, and Uniswap.

Google said the Coruna exploit kit cannot compromise devices running the latest version of iOS, making software updates one of the simplest ways for users to protect themselves.

the Google Threat Intelligence Group said in its report.

For users who cannot update their devices immediately, researchers also recommend enabling Lockdown Mode, a security feature designed to reduce exposure to targeted attacks.

Google said the discovery highlights how advanced cyber tools can be transferred between different actors, including surveillance companies, espionage groups, and financially motivated attackers.

The company said that sharing research on these exploit kits is intended to raise awareness and encourage stronger security practices across the industry.

For everyday iPhone users, researchers say the advice remains straightforward: keep devices updated, avoid suspicious websites, and enable additional security protections when possible.

Latest

Elon Musk tells his side of OpenAIs beginnings in trial pitting him against CEO Sam Altman

Elon Musk tells his side of OpenAI's beginnings in trial pitting him against CEO Sam Altman

Goa govt unveils draft AI policy with aim to position state as global hub for high-tech innovation

Goa govt unveils draft AI policy with aim to position state as global hub for high-tech innovation

Apple iPhone Ultra and MacBook Ultra maybe in the works, what to expect

Apple may be planning to stretch its “Ultra” branding beyond watches and chips, with a foldable iPhone and a premium touchscreen MacBook reportedly in the w

After firing 30,000, AWS CEO says AI isn’t replacing jobs and Amazon intends to hire 11,000

It’s all very confusing at the moment. Just weeks after Amazon completed layoffs totalling 30,000, AWS CEO Matt Garman has said that Amazon is now hiring 11,0

Google backs out of $100 million Pentagon challenge to build AI drones for US military because of ethics

Google has withdrawn from a $100 million Pentagon drone swarm challenge after internal review. The move highlights ongoing tensions in companies over AI use in

Topics

Siding with dictators not who we are: Ex-US envoy says Trump favoured Putin

Former US Ambassador to Ukraine Bridget Brink said she resigned from her post because Donald Trump repeatedly sided with Russian President Vladimir Putin, whom

Return the Kohinoor: Mamdani says he’d urge King Charles to hand diamond to India

New York City Mayor Zohran Mamdani said he would encourage King Charles to return the Koh-i-Noor Diamond during the monarch's US visit. Buckingham Palace declin

Alphabets first-quarter profit soars as Googles big AI bets help push stock to new highs

Alphabet's first-quarter profit soars as Google's big AI bets help push stock to new highs

Elon Musk tells his side of OpenAIs beginnings in trial pitting him against CEO Sam Altman

Elon Musk tells his side of OpenAI's beginnings in trial pitting him against CEO Sam Altman

Trump hosts NASA Artemis II astronauts at White House

Donald Trump hosted the Artemis II astronaut crew and NASA Administrator Jared Isaacman at the White House. The meeting spotlighted NASA's upcoming crewed Moon

Brazil Probe Ties JBS, Cargill to Vendors Linked to Slave Labor

JBS NV and Cargill Agrícola SA are defendants in a public civil action brought by Brazil prosecutors after authorities determined the companies had systematica

On witness stand, Elon Musk accuses Sam Altmans lawyer of trying to trick him

MUSK-OPENAI-COURT:On witness stand, Elon Musk accuses Sam Altman's lawyer of trying to trick him

IPL 2026: No respite for MI as 243 not enough against rampant SRH at Wankhede

IPL 2026: SunRisers Hyderabad extended their winning run in the Indian Premier League by recording the 4th highest chase in the history of the tournament. Chasi
spot_img

Related Articles

Popular Categories

spot_imgspot_img