Three Buddy Problem

Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery

Mar 5, 2026
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Coruna Looks Like Leaked Nation-State Engineering

  • Matthias suspects Coruna derives from a nation-state surveillance framework because of modular, bureaucratic engineering and matching timelines.
  • He notes core framework builds trace to older iOS versions while modules target later SDKs, matching reported L3/Peter Williams leaks.
INSIGHT

Secondary Market Enables Exploit Proliferation

  • Exploit resale and brokers create a secondary market enabling reuse of high-end iOS exploits by other states or criminals.
  • Matthias cites prior reuse of NSO/Intellects WebKit exploits and mentions sanctioned brokers filling markets for non-NATO buyers.
INSIGHT

Framework Engineering Outweighs Individual Exploits

  • The expensive part is the modular framework that composes many exploits into chains and plugs in targeting modules, not each vuln alone.
  • Matthias explains modules let low-skill operators target specific apps like Binance or MetaMask by hooking targeted functions.
Get the Snipd Podcast app to discover more snips from this episode
Get the app