CVE-2016-4655
apple iphone os
Published 25 Aug 2016 · updated 17 Jun 2026 · Analyzed
5.5 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 24 May 2022, with a remediation deadline of 14 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
References
- lists.apple.com/archives/security-announce/2016/Aug/msg00000.html · Broken Link, Mailing List, Vendor Advisory
- lists.apple.com/archives/security-announce/2016/Sep/msg00005.html · Broken Link, Mailing List, Vendor Advisory
- www.securityfocus.com/bid/92651 · Broken Link, Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/92965 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1036694 · Broken Link, Third Party Advisory, VDB Entry
- blog.lookout.com/blog/2016/08/25/trident-pegasus/ · Broken Link
- support.apple.com/HT207107 · Vendor Advisory
- support.apple.com/HT207145 · Vendor Advisory
- www.exploit-db.com/exploits/44836/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4655 · US Government Resource