logoalt Hacker News

Apple releases iOS 15.8.7 to fix Coruna exploit for iPhone 6S from 2015

88 pointsby seam_carvertoday at 1:22 AM35 commentsview on HN

Comments

suprstarrdtoday at 1:42 AM

To be clear: the phone is from 2015, not the exploit chain.

Related: https://cloud.google.com/blog/topics/threat-intelligence/cor...

tech234atoday at 2:35 AM

Notably these exploits were originally patched for newer devices in 2023 and 2024. However, the Coruna exploits are now publicly available because some of the IOC URLs mentioned in Google's recent blog post [1] were found to still be live. Jailbreakers are already repurposing the code to make web-based tools [2].

[1]: https://cloud.google.com/blog/topics/threat-intelligence/cor...

[2]: https://x.com/Little_34306/status/2031823581513204009 (Note: the link in this tweet goes to an exploit page that uses code repurposed from malware)

show 1 reply
seam_carvertoday at 2:30 AM

Available for:

iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

iOS 16.7.15 and iPadOS 16.7.15: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

GeekyBeartoday at 3:04 AM

A security update for an eleven year old phone is pretty wild.

For comparison, the Nexus 6P was released in the same year as the iPhone 6S. It last received a security update in 2018.

show 2 replies
ryandraketoday at 3:33 AM

This is nice in that Apple acknowledges that iPhone 6s and iPhone 7 devices still exist and are used. I wish third party developers would read that memo and get with the program. The App Store is becoming a ghost town of "This app stopped supporting your icky old device" warning messages due to app developers abandoning these phones.

show 2 replies
thecybernerdtoday at 1:40 AM

I wonder what the active device threshold is for them to make the decision to patch an operating system from a decade ago.

show 1 reply
kevincloudsectoday at 3:19 AM

patching a kernel exploit on a phone from 2015 is nice until you realize the coruna IOC URLs were still live long enough for jailbreakers to weaponize the code before the patch shipped.

throwaway85825today at 2:39 AM

A device can be unsupported yet millions will still use it. The obsolescence business model needs to be legislated away.

show 1 reply
nineteen999today at 3:14 AM

Now if they'd just release an update to 26.3.1 (23D8133) which PERMANENTLY broke Apple Carplay for me I'd be happy. It's been getting steadily worse since iOS 26 was released.

Apple is rapidly becoming the new Microsoft. I mean, Microsoft has fallen so much further, so I guess that just opened up a new gap in the shitty technology spectrum for Apple to descend to.

burnt-resistortoday at 2:09 AM

Still waiting for iOS and iPadOS security updates to 18 as per the tradition of supporting the past 2 generations of OSes rather than this sneaky rug-pull of trying to foist fugly 26 on users who don't want an unusable device.

This sort of spurious patching and releasing token cheap devices is a form of gaslighting.

behnamohtoday at 1:40 AM

Am I supposed to be impressed by this? This is part of the Apple experience: long-term updates in exchange for absurdly high markups up-front. I'd be impressed if the markup got lowered and iDevices still got such updates, but that's not happening.

show 6 replies
anshumankmrtoday at 2:21 AM

This will really help the 10 people still using an iPhone 6S.

(Still a common W for Apple updates)