CVE-2016-1736 describes a memory corruption vulnerability in the Bluetooth component of Apple OS X prior to version 10.11.4. An attacker could exploit this flaw by enticing a user to run a specially crafted application. Successful exploitation could lead to arbitrary code execution with elevated privileges or a denial of service. The vulnerability has a CVSSv3 score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and resulting in high impact to confidentiality, integrity, and availability. There is no public exploit code available, nor any evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.11.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.