CVE-2016-4622

HIGH

Safari < 9.1.2 - Remote Code Execution via Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2016-4622. PoCs published by saelo, hdbreaker.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2016-4622, a vulnerability in JavaScriptCore (WebKit) that allows arbitrary memory read/write. The exploit leverages type confusion in array operations to achieve remote code execution.

Description

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.

Exploits (2)

nomisec WORKING POC 109 stars
by saelo · poc
https://github.com/saelo/jscpwn

This repository contains a functional exploit PoC for CVE-2016-4622, a vulnerability in JavaScriptCore (WebKit) that allows arbitrary memory read/write. The exploit leverages type confusion in array operations to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: WebKit JavaScriptCore (Safari, other WebKit-based browsers)
No auth needed
Prerequisites: Victim must visit a malicious webpage · WebKit-based browser with vulnerable JavaScriptCore
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 22 stars
by hdbreaker · poc
https://github.com/hdbreaker/WebKit-CVE-2016-4622

This repository contains functional exploit code demonstrating CVE-2016-4622, a memory disclosure vulnerability in WebKit's JavaScript Core engine. The exploit leverages a race condition in the Array.slice() implementation to leak adjacent memory contents.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WebKit JavaScript Core (JSC)
No auth needed
Prerequisites: WebKit JavaScript Core (JSC) environment · Ability to execute JavaScript code
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-16-485
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00003.html
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91830
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206900
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036343
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/539295/100/0/threaded
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-16-486
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206905
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT206902
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Jul/msg00004.html

Scores

CVSS v3 8.8
EPSS 0.1884
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (3)
apple/iphone_os < 9.3.3
apple/safari < 9.1.2
apple/tvos < 9.2.2
Published Jul 22, 2016
Tracked Since Feb 18, 2026