CVE-2016-4657
KEV PoC ×2massMemory Corruption RCE in Apple iOS WebKit (CVE-2016-4657)
CISA: Apple iOS Webkit Memory Corruption Vulnerability
WebKit, the browser engine used by Safari and other apps on Apple iOS, contains a memory corruption flaw (CWE-787, out-of-bounds write) affecting all iOS versions before 9.3.5. The flaw is triggered when a user visits a crafted website, causing corruption within the WebKit process. A successful attacker can execute arbitrary code in the context of the browser or cause a denial of service, a typical first stage in a full device compromise. All iPhone, iPad, and iPod touch users running iOS earlier than 9.3.5 are affected. The vulnerability has been exploited in the wild (CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-05-24, with public PoC/exploit references available) and EPSS estimates a 66.8% probability of exploitation within 30 days.
What to do: Update all iPhones, iPads, and iPod touches to iOS 9.3.5 or later, and verify fleet versions via Settings > General > About. Devices with hardware that cannot run iOS 9.3.5+ remain permanently exposed, so consider isolating or retiring them. Until patched, reduce risk by avoiding untrusted websites in Safari and other WebKit-based apps.
| Apple iPhone OS (iOS) - WebKit component, used by Safari and WebKit-based apps | All iOS versions before 9.3.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
- Affected
- Apple iOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- iphone os
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H