< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

iOS security vulnerabilities found in OpenClaw and Coruna-iOS-C2

Critical security vulnerabilities have been identified in two iOS-based systems, OpenClaw and Coruna-iOS-C2, posing significant risks to user data and infrastructure control.

OpenClaw for iOS is affected by CVE-2026-100551, a vulnerability with a CVSS score of 9.0. The flaw stems from inconsistent enforcement of stored TLS pins within the app. This allows attackers to inject a manipulated control interface under certain conditions, potentially intercepting gateway tokens or passwords. The vulnerability affects versions from 2026.7.1 to 2026.8.10, and a fix was released in version 2026.8.11.

Separately, the Coruna-iOS-C2 system contains a vulnerability involving insecure static resource paths. Attackers can access sensitive files, such as .env and .db files, which contain environment variables, configuration keys, user account hashes, and two-factor authentication (2FA) keys. Because Coruna-iOS-C2 serves as a command-and-control system for infrastructure, these leaks could allow unauthorized access to administrative interfaces and managed infrastructure data.

Entities

Apple · Coruna-iOS-C2 · OpenClaw