CVE-2016-7660

HIGH

iPhone OS < 10.2, macOS < 10.12.2, watchOS < 3.1.3 - Local Privilege Escalation via Syslog Mach Port Name References

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-7660. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit demonstrates a Mach port deallocation vulnerability in syslogd (CVE-2016-7660) by spoofing a MACH_NOTIFY_DEAD_NAME message, allowing an attacker to free an arbitrary port name and potentially replace it with a controlled port. The PoC targets macOS Sierra 10.12.1 and leverages the com.apple.system.logger service.

Description

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · cdosmultiple
https://www.exploit-db.com/exploits/40959

This exploit demonstrates a Mach port deallocation vulnerability in syslogd (CVE-2016-7660) by spoofing a MACH_NOTIFY_DEAD_NAME message, allowing an attacker to free an arbitrary port name and potentially replace it with a controlled port. The PoC targets macOS Sierra 10.12.1 and leverages the com.apple.system.logger service.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: macOS syslogd (10.12.1)
No auth needed
Prerequisites: Access to the com.apple.system.logger Mach service · Ability to send Mach messages
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207487
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207422
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94905
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40959/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037469
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT207423

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 40.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (3)
apple/iphone_os < 10.1.1
apple/mac_os_x < 10.12.1
apple/watchos < 2.2.2
Published Feb 20, 2017
Tracked Since Feb 18, 2026