ZeroHour

CVE-2016-4656

KEV PoC mass

Kernel Memory Corruption in Apple iOS Enables Privileged Code Execution

CISA: Apple iOS Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
24%p98
Published
()
KEV added
AI analysis

CVE-2016-4656 is a memory corruption flaw in the Apple iOS kernel (CWE-264, permissions/privilege handling) that can be triggered by a crafted or untrusted application running on the device. A successful exploit lets the attacker execute arbitrary code in the privileged kernel context, effectively giving full control of the device, or alternatively crash it to cause a denial of service. Any iPhone, iPad or iPod touch running an iOS version before the August 2016 fix, iOS 9.3.5, is affected. The flaw is confirmed exploited in the wild: it was one of the 'Trident' chain used in the 2016 Pegasus spyware attacks (chained with the WebKit flaw CVE-2016-4657, delivered via malicious links), and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-24; EPSS of ~24% (98th percentile) indicates continued exploitation risk.

What to do: Update all iPhones, iPads and iPod touches to iOS 9.3.5 or later (or any currently supported iOS/iPadOS release) per the CISA-required action; there is no reliable workaround for a kernel memory-corruption flaw. Inventory for legacy devices that cannot upgrade beyond iOS 9.3.4 or earlier and retire or isolate them, and since this bug was used in targeted Pegasus spyware campaigns, review high-risk or targeted users' devices for signs of compromise.

Affected
Apple iOSiOS versions prior to 9.3.5 (fixed in iOS 9.3.5, August 2016; iPhone 4s and later, iPad 2 and later, iPod touch 5th generation and later)
Estimated exposure
masshundreds of millions of iOS devices at disclosure (of Apple's ~1 billion active-device install base in 2016); remaining unpatched legacy devices today likely… — Apple's active install base surpassed one billion devices in early 2016, overwhelmingly iOS, and every device on a pre-9.3.5 build was exposed until patched, so the plausible affected population is in the hundreds of millions with only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CISA Known Exploited Vulnerability
Affected
Apple iOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news