Apple just pushed emergency security updates to older iPhones and iPads — devices that can’t run iOS 17 or later — to patch an actively exploited vulnerability. The flaw, tracked as CVE-2025-24201, targets WebKit, the browser engine underpinning Safari and every other browser on Apple’s platforms. It’s already been used in real-world attacks.
The updates, iOS 15.8.4, iOS 16.7.11, iPadOS 15.8.4, and iPadOS 16.7.11, landed on March 12, 2025. They’re not routine maintenance releases. They exist because someone found a way to break out of WebKit’s sandbox — the protective boundary that’s supposed to keep web content from touching the rest of the operating system.
What the Coruna Exploit Actually Does
Apple’s advisory describes the vulnerability as an out-of-bounds write issue in WebKit. In plain terms: malicious web content can write data outside the memory region it’s supposed to occupy, and from there, escape the Web Content sandbox entirely. That’s a serious escalation. A sandbox escape means an attacker who initially only has access to the browser’s limited environment can potentially reach system-level resources — files, sensors, other apps.
According to AppleInsider, Apple acknowledged that this vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.” That phrasing matters. It signals a targeted operation, likely state-sponsored or carried out by a commercial spyware vendor, not a broad consumer threat. But the patch going out to older devices means the attack surface was wide enough to warrant action.
Apple originally addressed CVE-2025-24201 in iOS 17.2 back in December 2023, then issued a supplementary fix in iOS 18.3.2 on March 4, 2025. The March 12 updates backport those protections to hardware stuck on iOS 15 and 16 — think iPhone 6s, iPhone 7, the original iPhone SE, and older iPad models.
The fix involves improved bounds checking to prevent the out-of-bounds write. Standard mitigation for this class of bug. But the fact that Apple is actively maintaining security patches for devices it stopped supporting with major OS updates years ago tells you something about the severity.
Why Older Devices Are Especially Vulnerable
Here’s the uncomfortable reality: millions of people are still using iPhones that can’t run anything newer than iOS 16. Some by choice. Many because they can’t afford to upgrade. These devices don’t get the latest security architecture improvements, the newer lockdown features, or the hardened WebKit protections that shipped with iOS 17 and 18. They’re running with older compilers, older exploit mitigations, older everything.
And they’re targets.
Commercial spyware firms like NSO Group have historically favored exactly this kind of attack chain — a WebKit initial access vector followed by a sandbox escape, then a privilege escalation to achieve full device compromise. The pattern is well-documented by organizations like Citizen Lab at the University of Toronto, which has tracked dozens of such campaigns against journalists, activists, and political figures.
Apple didn’t attribute the Coruna exploit to any specific group. It rarely does. But the “extremely sophisticated attack against specific targeted individuals” language is the same template Apple uses when describing operations linked to mercenary spyware. Apple’s own security advisory page confirms the vulnerability details and affected devices.
So if you’re managing a fleet of older Apple devices — in education, healthcare, enterprise environments — this patch isn’t optional. It’s urgent. The attack requires only that a user visit a crafted webpage. No app install. No user interaction beyond clicking a link.
The affected device list is extensive: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) on the iOS 15 side. For iOS 16, it covers iPhone 8, iPhone 8 Plus, iPhone X, and several iPad models including the 5th generation iPad and iPad Pro variants.
That’s not a small install base.
The Bigger Picture on Apple’s Backport Strategy
Apple’s decision to backport this fix is notable because it breaks from the company’s general posture of nudging users toward the latest hardware and software. Typically, once a device falls off the supported OS list, it receives only sporadic security patches — if any. The Coruna exploit apparently crossed whatever internal threshold Apple uses to justify the engineering effort of maintaining these older branches.
This isn’t unprecedented. Apple backported fixes for the FORCEDENTRY exploit (used by NSO Group’s Pegasus) to older iOS versions in 2021. It did the same for a handful of WebKit zero-days in 2022 and 2023. But each instance reinforces an awkward truth: Apple’s security model depends on users running current software on current hardware, and a significant portion of its user base does neither.
For IT administrators, the action item is straightforward. Push these updates immediately through MDM or direct notification. For individual users on older devices, go to Settings > General > Software Update. Now. Not later.
The exploit is real. It’s been used. And the only thing standing between an older iPhone and a compromised one is a software update that takes a few minutes to install.


WebProNews is an iEntry Publication