Release 7.7.0
Overview
Corellium 7.7 delivers a streamline, high value update for mobile security teams. The release brings support for the latest mobile operating systems -iOS and iPad OS 18.7 as well as 26.0- so you can test, debug, and reverse-engineer on the newest platforms right away. A new MATRIX risk score is now displayed for every app, giving you an instant gauge of risk and the ability to track progress across multiple releases and tests runs. Additionally, creating a new virtual device has become more flexible: you can now specify the primary storage size directly in the Advanced Boot Options and Configure Your Device pages, with appropriate UI choices for iOS, Android, and IoT devices. Together, these enhancements make Corellium 7.7 a powerful, user-friendly platform for the modern threat landscape.
Mobile Model Support
We've expanded our platforms compatibility with the latest mobile models:
iPhone
- iPhone 17
- iPhone 17 Pro
- iPhone 17 Pro Max
- iPhone Air
Corellium's Support for Apple's Memory Integrity Enforcement on iPhone 17 Models
Corellium delivers support for Apple's Memory Integrity Enforcement (MEI) by leveraging Arm's Memory Tagging Extension (MTE) architecture. Corellium has implemented an instruction-only MTE mode that allows iPhone 17 models to execute MIE instructions, although the hardware-enforced tag checks are disabled. Because the MTE implementation does not enforce tag validation, researchers can run and observe MIE instructions in iPhone 17 models but cannot exercise or evaluate the actual enforcement semantics that would be present on fully-supported Apple hardware. This setup enables exploration of MIE instruction behavior and its integration with Apple's runtime, while transparently communicating the limitation that enforcement is not available in the current Corellium environment.
Mobile OS Support
We've expanded our platform's compatibility wiht the latest mobile operating system version:
Android
- Android 16
iOS/iPad OS
- iOS 15.8.5
- iOS 16.7.12
- iOS/iPad OS 18.7.x
- iOS/iPad OS 26.0.x
New Features
User Resizable Devices
New Primary Storage Volume Selection
- Flexible Storage Sizing - When creating a new virtual device, you can now specify the size of the primary storage volume diectly in the Advanced Boot Opions and Configure Your Device pages.
- Platform-specific UI
- iOS & Android - Dropdown lists of supported sizes (based on the selected flavor)
- IoT - Either a text input with step-increments (if the flavor defines min/max/step) or a pre-configured dropdown list.
- If your license has MATRIX enabled, you'll see a MATRIX warning when selecting cores, RAM, and storage.
- If MATRIX is not enabled, the warning is omitted.
MATRIX Score
- Risk-Based Scoring - The MATRIX Score is a real-time, computed "risk score" that calculates based on the number of vulnerabilities and their secerity levels identified during a mobile application security test.
- Dynamic Updating - As your AppSec team nullifies findings or adjusts severities, the score is refreshed automatically to reflect the current risk posture.
- Audit-Ready Log - Every modification (nullification, severity change, evidence edit) is recorded in an immutable audit trail, ensuring full traceability for compliance and governance.
How It Works
- Run a Test - Perform a standard MATRIX test on your mobile app.
- Review Findings - Inspect the findings list; each item carries a severity weight.
- Adjust Findings - Nullify or re-severity findings directly in the UI.
- See the Score Update - The MATRIX Score panel updates instantly, giving you a live view of your app's risk level.
- Audit Trail - Click the "Activity" tab in the report to view every change made to the findings, with timestamps, name of the user, and action details.
Benefits
- Immediate Visibility - Quickly gauge how remediation actions impact overall risk.
- Prioritization Aid - Use the score to focus resources on high-impact vulnerabilities.
- Compliance-Ready - The audit log provides the evidence needed for security audits and regulatory reporting.
- High-Level KPI - Provides a key performance indicator to track risk trends over time thoughout the software development lifecycle.
Other Enhancements
Bug Fixes and UI Enhancements
Various underlying bugs have been resolved to improve stability and performance. Minor user interface tweaks have been implemented for a more intuitive and user-friendly experience.