CVE-2016-4657
HIGH KEV RANSOMWAREApple Iphone OS < 9.3.5 - Out-of-Bounds Write
Title source: ruleDescription
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Exploits (6)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremoteios
https://www.exploit-db.com/exploits/44836
References (8)
Scores
CVSS v3
8.8
EPSS
0.7943
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-05-24
VulnCheck KEV
2016-08-15
InTheWild.io
2016-08-15
ENISA EUVD
EUVD-2016-5643
Ransomware Use
Confirmed
CWE
CWE-787
Status
published
Products (1)
apple/iphone_os
< 9.3.5
Published
Aug 25, 2016
KEV Added
May 24, 2022
Tracked Since
Feb 18, 2026