CVE-2016-4655
KEV PoC massKernel Information Disclosure in Apple iOS
CISA: Apple iOS Information Disclosure Vulnerability
CVE-2016-4655 is an information-disclosure vulnerability (CWE-200) in the Apple iOS kernel that allows attackers to obtain sensitive information from kernel memory via a crafted application. It is triggered when a user runs a malicious, crafted app on the device; the app can then read kernel memory, gaining access to sensitive contents such as kernel data and addresses that can help defeat protections like address-space layout randomization as part of a broader attack chain. Any iPhone, iPad, or iPod touch running an affected, unpatched iOS version is affected, though the source data does not specify exact version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24), indicating known in-the-wild exploitation, and EPSS assigns a 33.4% probability of exploitation within 30 days (98th percentile). Public reporting documented this flaw as part of the 2016 'Trident' exploit chain used by Pegasus spyware, alongside sibling iOS kernel and WebKit flaws.
What to do: Per the CISA KEV required action, apply Apple's iOS security updates per vendor instructions: identify any iPhones, iPads, or iPod touches still running unpatched 2016-era iOS builds (via MDM or device inventory) and update them to the newest iOS release each device supports. Prioritize remediation, since exploitation is already known in the wild and EPSS is elevated; no workaround information is available in the source data.
| Apple iOS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
- Affected
- Apple iOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- iphone os
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N