
Three Buddy Problem Matthias Frielingsdorf on the mysterious Coruna iOS exploit kit discovery
Mar 5, 2026
AI Snips
Chapters
Transcript
Episode notes
Coruna Looks Like Leaked Nation-State Engineering
- Matthias suspects Coruna derives from a nation-state surveillance framework because of modular, bureaucratic engineering and matching timelines.
- He notes core framework builds trace to older iOS versions while modules target later SDKs, matching reported L3/Peter Williams leaks.
Secondary Market Enables Exploit Proliferation
- Exploit resale and brokers create a secondary market enabling reuse of high-end iOS exploits by other states or criminals.
- Matthias cites prior reuse of NSO/Intellects WebKit exploits and mentions sanctioned brokers filling markets for non-NATO buyers.
Framework Engineering Outweighs Individual Exploits
- The expensive part is the modular framework that composes many exploits into chains and plugs in targeting modules, not each vuln alone.
- Matthias explains modules let low-skill operators target specific apps like Binance or MetaMask by hooking targeted functions.
