CVE-2016-4655

MEDIUM KEV RANSOMWARE

WebKit not_number defineProperties UAF

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2016-4655 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 24, 2022, with confirmed use in ransomware campaigns. EIP tracks 3 public exploits from researchers including Metasploit, jndok, Cryptiiiic.

AI-analyzed exploit summary This Metasploit module exploits a use-after-free (UAF) vulnerability in WebKit's JavaScriptCore library (CVE-2016-4657) to achieve remote code execution on iOS devices. It leverages memory corruption techniques to bypass mitigations and execute arbitrary payloads.

Description

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteios
https://www.exploit-db.com/exploits/44836

This Metasploit module exploits a use-after-free (UAF) vulnerability in WebKit's JavaScriptCore library (CVE-2016-4657) to achieve remote code execution on iOS devices. It leverages memory corruption techniques to bypass mitigations and execute arbitrary payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: WebKit (JavaScriptCore) on Apple iOS
No auth needed
Prerequisites: Target must visit a malicious webpage or open a crafted link · Vulnerable version of WebKit on iOS
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 101 stars
by jndok · local
https://github.com/jndok/PegasusX

This repository contains a functional local privilege escalation (LPE) exploit for CVE-2016-4655 and CVE-2016-4656 on OS X 10.11.6. The exploit leverages kernel memory corruption via IOKit to achieve arbitrary code execution in kernel mode.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Apple OS X 10.11.6
No auth needed
Prerequisites: Access to a vulnerable OS X 10.11.6 system
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 10 stars
by Cryptiiiic · poc
https://github.com/Cryptiiiic/skybreak

This repository contains a functional exploit for CVE-2016-4655, targeting iOS 8.4.1. The exploit leverages a kernel memory leak vulnerability in the IOKit framework to extract the kernel slide (kslide) value, which is a critical step in bypassing kernel address space layout randomization (KASLR).

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Apple iOS 8.4.1
No auth needed
Prerequisites: Physical or remote access to a vulnerable iOS device running 8.4.1 · Ability to execute arbitrary code on the device (e.g., via a userland exploit)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (10)

Core 10
Core References
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Sep/msg00005.html
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44836/
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92651
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207107
Mailing List, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2016/Aug/msg00000.html
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036694
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92965
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207145

Scores

CVSS v3 5.5
EPSS 0.8209
EPSS Percentile 99.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2022-05-24
VulnCheck KEV 2016-08-15
InTheWild.io 2016-08-15
ENISA EUVD EUVD-2016-5641
Ransomware Use Confirmed
Status published
Products (2)
apple/iphone_os 10.0
apple/iphone_os < 9.3.5
Published Aug 25, 2016
KEV Added May 24, 2022
Tracked Since Feb 18, 2026