ZeroHour

CVE-2016-4657

KEV PoC ×2mass

Memory Corruption RCE in Apple iOS WebKit (CVE-2016-4657)

CISA: Apple iOS Webkit Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
67%p99
Published
()
KEV added
AI analysis

WebKit, the browser engine used by Safari and other apps on Apple iOS, contains a memory corruption flaw (CWE-787, out-of-bounds write) affecting all iOS versions before 9.3.5. The flaw is triggered when a user visits a crafted website, causing corruption within the WebKit process. A successful attacker can execute arbitrary code in the context of the browser or cause a denial of service, a typical first stage in a full device compromise. All iPhone, iPad, and iPod touch users running iOS earlier than 9.3.5 are affected. The vulnerability has been exploited in the wild (CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-05-24, with public PoC/exploit references available) and EPSS estimates a 66.8% probability of exploitation within 30 days.

What to do: Update all iPhones, iPads, and iPod touches to iOS 9.3.5 or later, and verify fleet versions via Settings > General > About. Devices with hardware that cannot run iOS 9.3.5+ remain permanently exposed, so consider isolating or retiring them. Until patched, reduce risk by avoiding untrusted websites in Safari and other WebKit-based apps.

Affected
Apple iPhone OS (iOS) - WebKit component, used by Safari and WebKit-based appsAll iOS versions before 9.3.5
Estimated exposure
masshundreds of millions of iOS devices were on affected builds at disclosure; the number still running iOS < 9.3.5 today is unknown but plausibly in the hundreds… — iOS ran on hundreds of millions of active iPhones/iPads when the flaw was disclosed in 2016 and every release before 9.3.5 is affected, though devices capped on old iOS builds that can no longer update are the residual exposed population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CISA Known Exploited Vulnerability
Affected
Apple iOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news