CVE-2016-4657

HIGH KEV RANSOMWARE

Apple Iphone OS < 9.3.5 - Out-of-Bounds Write

Title source: rule

Description

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteios
https://www.exploit-db.com/exploits/44836
exploitdb WORKING POC
by qwertyoruiop · htmldoshardware
https://www.exploit-db.com/exploits/44213
nomisec WORKING POC 56 stars
by iDaN5x · client-side
https://github.com/iDaN5x/Switcheroo
nomisec WRITEUP 9 stars
by viai957 · client-side
https://github.com/viai957/webkit-vulnerability
nomisec STUB 3 stars
by Mimoja · client-side
https://github.com/Mimoja/CVE-2016-4657-NintendoSwitch

Scores

CVSS v3 8.8
EPSS 0.7943
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-05-24
VulnCheck KEV 2016-08-15
InTheWild.io 2016-08-15
ENISA EUVD EUVD-2016-5643
Ransomware Use Confirmed
CWE
CWE-787
Status published
Products (1)
apple/iphone_os < 9.3.5
Published Aug 25, 2016
KEV Added May 24, 2022
Tracked Since Feb 18, 2026