ZeroHour

CVE-2016-4655

KEV PoC mass

Kernel Information Disclosure in Apple iOS

CISA: Apple iOS Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
33%p98
Published
()
KEV added
AI analysis

CVE-2016-4655 is an information-disclosure vulnerability (CWE-200) in the Apple iOS kernel that allows attackers to obtain sensitive information from kernel memory via a crafted application. It is triggered when a user runs a malicious, crafted app on the device; the app can then read kernel memory, gaining access to sensitive contents such as kernel data and addresses that can help defeat protections like address-space layout randomization as part of a broader attack chain. Any iPhone, iPad, or iPod touch running an affected, unpatched iOS version is affected, though the source data does not specify exact version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24), indicating known in-the-wild exploitation, and EPSS assigns a 33.4% probability of exploitation within 30 days (98th percentile). Public reporting documented this flaw as part of the 2016 'Trident' exploit chain used by Pegasus spyware, alongside sibling iOS kernel and WebKit flaws.

What to do: Per the CISA KEV required action, apply Apple's iOS security updates per vendor instructions: identify any iPhones, iPads, or iPod touches still running unpatched 2016-era iOS builds (via MDM or device inventory) and update them to the newest iOS release each device supports. Prioritize remediation, since exploitation is already known in the wild and EPSS is elevated; no workaround information is available in the source data.

Affected
Apple iOS
Estimated exposure
mass>1M users/devices (Apple's iOS install base exceeds 1 billion active devices; the still-vulnerable share is unpatched legacy devices) — Estimate based on Apple's billion-plus active iOS device install base: even the fraction of devices still running unpatched 2016-era versions plausibly numbers in the millions, though the precise count is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

CISA Known Exploited Vulnerability
Affected
Apple iOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news