THREATS AND VULNERABILITIES

Actively Exploited iPhone Vulnerabilities: Business Patch Tracker

An exploited-vulnerability list is useful only when it produces an accountable device decision. Businesses need to know which iPhones can reach company data, the installed build, whether Apple still supports the model, the remediation deadline, and what access changes if the update fails.

This tracker highlights selected iOS vulnerabilities for which Apple, CISA, or cited primary research published exploitation information. It is dated July 31, 2026. It is not a complete vulnerability database and must be checked against Apple’s current security releases and product advisories before use.

Current review workflow

  1. Check Apple’s security releases page for the latest supported iOS release.
  2. Open the product-specific Apple advisory and confirm the affected products and fixed release.
  3. Review CISA’s Known Exploited Vulnerabilities information when the CVE is listed.
  4. Compare the advisory with a current device and OS-build inventory.
  5. Set a deadline based on exploitation evidence, exposure, and business consequence.
  6. Enforce access restrictions or a time-limited exception when remediation cannot complete.
  7. Retain evidence showing the device actually installed the update.

Selected exploited-iOS records

CVE or research set Public exploitation statement Defensive decision
CVE-2025-43200 Apple said a malicious iCloud Link media issue may have been exploited in an extremely sophisticated targeted attack; fixed in iOS 18.3.1 High-risk users should have moved beyond the historical fixed release; investigate authentic threat notifications
CVE-2025-43300 Apple said malicious image processing may have been used in an extremely sophisticated targeted attack; addressed in iOS 18.6.2 and corresponding releases Validate current supported release and accelerate any exception
CVE-2025-43529 and CVE-2025-14174 Apple documented exploitation statements in the iOS 26.2 advisory; GTIG connected the vulnerabilities to DarkSword research Verify current iOS 26 or supported iOS 18 protections, with priority for high-risk users
DarkSword six-vulnerability chain GTIG reported a web-delivered full chain affecting iOS 18.4 through 18.7 and said all six issues were patched by iOS 26.3, most earlier Do not use a copied static safe-version rule; compare every device with current Apple releases
Coruna exploit kit GTIG reported five chains and 23 exploits targeting iOS 13 through 17.2.1; current iOS was unaffected at report time Remove unsupported and persistently outdated devices from trusted access
CVE-2023-41991, CVE-2023-41992, CVE-2023-41993 Google reported a 2023 Predator chain; Apple patches addressed the issues Use as historical evidence that targeted chains combine delivery, browser, and kernel flaws
Mobile vulnerability operations correlating Apple advisory status, CISA exploited evidence, device inventory, remediation deadline, and access enforcement
Mobile vulnerability operations correlating Apple advisory status, CISA exploited evidence, device inventory, remediation deadline, and access enforcement.

Source notes for the tracker

Apple’s iOS 18.3.1 advisory documents CVE-2025-43200 and an exploitation statement. Citizen Lab later reported a forensic case it attributed to Graphite and said Apple confirmed the zero-click vector was mitigated in that release.

Apple’s iOS 18.6.2 advisory documents CVE-2025-43300 and states that a malicious image may have been exploited in an extremely sophisticated attack against specific targeted individuals.

The iOS 26.2 advisory contains Apple exploitation statements for CVE-2025-43529 and CVE-2025-14174. Google’s DarkSword research provides broader chain context and affected-version reporting. Apple’s later iOS 18.7.7 advisory records additional protections for supported older devices.

Google’s Coruna report describes extensive reuse of vulnerabilities against older software. The older Google Predator analysis illustrates a separate exploit chain and should not be merged with DarkSword, Coruna, or Graphite.

CISA added Apple vulnerabilities to its catalog in notices including the April 17, 2025 KEV alert. Federal deadlines apply to covered federal agencies; other organizations can use KEV status as a strong prioritization signal, not as a complete statement of their obligations.

Turn the tracker into an operational control

Use the business iPhone software-update management guide to connect vulnerability intelligence to device inventory, risk-based deadlines, MDM enforcement, exceptions, and installed-build evidence. The BLASTPASS case review shows why a published fix still needs an operational path to every affected device.

Maintain a device-to-advisory join

The vulnerability owner should be able to join Apple model and build information with the installed fleet. A percentage such as “95% compliant” can hide the only exposed executive or administrator phone. Track each overdue device, the services it reaches, and the named exception owner.

Separate “update available” from “update installed”

Sending a notification, scheduling an MDM command, or seeing a pending status is not remediation. Require a later check-in showing the installed build. Sample devices to validate the console. Stale devices should not be counted as healthy.

Define accelerated deadlines

The patch policy should specify what active exploitation changes. High-risk users and Internet-exposed business access may need direct same-day support, while lower-risk devices may follow a short tested window. The organization should be able to restrict access when the deadline expires.

Manage unsupported devices

Apple sometimes ships security updates for older operating-system branches, but coverage changes. Confirm the exact model and advisory. If a phone cannot receive the required protection, replace it, remove business data, or document short-lived compensating controls and a replacement date.

Evidence leaders should request

  • timestamped device inventory with model, build, owner, and last check-in;
  • the Apple or CISA source used to classify urgency;
  • change or deployment record showing the update command;
  • post-update report proving installed build;
  • named exceptions with business access, safeguards, and expiration;
  • test showing a noncompliant device loses the intended access;
  • incident review for any device that was exposed during a targeted campaign.

Use the iPhone Security Review Checklist for an individual settings review and the mobile-device security assessment for initial governance questions. Neither replaces current advisories, MDM evidence, or a professional assessment.

Sources

Audit the evidence behind mobile patching

OC Security Audit can test whether inventory, deadlines, enforcement, exceptions, and executive reporting work as designed. Contact OC Security Audit and learn about Ali Hassani, CISO, for an experienced, business-focused security review.

Update and correction history

  • August 2026: Apple source links were revalidated and updated to current official canonical destinations; the surrounding analysis and conclusions were unchanged.
  • July 2026: Initial tracker created and fact-checked against primary sources through July 31, 2026. Revalidate current Apple releases before relying on any historical fixed version.