CVE-2016-4622
HIGHSafari < 9.1.2 - Remote Code Execution via Memory Corruption
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2016-4622. PoCs published by saelo, hdbreaker.
AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2016-4622, a vulnerability in JavaScriptCore (WebKit) that allows arbitrary memory read/write. The exploit leverages type confusion in array operations to achieve remote code execution.
Description
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.
Exploits (2)
This repository contains a functional exploit PoC for CVE-2016-4622, a vulnerability in JavaScriptCore (WebKit) that allows arbitrary memory read/write. The exploit leverages type confusion in array operations to achieve remote code execution.
This repository contains functional exploit code demonstrating CVE-2016-4622, a memory disclosure vulnerability in WebKit's JavaScript Core engine. The exploit leverages a race condition in the Array.slice() implementation to leak adjacent memory contents.
References (12)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H