logo

CVE-2023-41974: The Apple iOS Kernel Flaw That Came Back to Bite

ID: 31ffdc91-c11b-5438-8904-8d0168998d84

STIX ID: report--31ffdc91-c11b-5438-8904-8d0168998d84

Feed Name: NoHackie

Threat Score
88/100

Date Published: 2026-03-09

Date Updated: 2026-04-19

...
...

CVE-2023-41974 is a physical use-after-free in Apple’s XNU kernel patched in iOS/iPadOS 17.0 but weaponized years later via the kfd/Landa proof-of-concept and incorporated into the commercial Coruna exploit kit; Coruna delivered a PlasmaLoader payload that hooks cryptocurrency wallets and exfiltrates seed phrases, was observed in targeted and mass watering-hole campaigns, and led CISA to add the CVE to its KEV catalog due to confirmed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.