CVE-2016-1757 describes a race condition vulnerability within the kernel of Apple iOS before 9.3 and OS X before 10.11.4. This flaw allows an attacker to execute arbitrary code with privileged context through a specially crafted application. With a CVSS score of 7.0 (HIGH), exploitation requires local access and user interaction (UI:R), but can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While not on CISA's KEV catalog, exploit code is publicly available on ExploitDB (EDB-39595, EDB-39741), and it has garnered significant community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.2.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
<= 10.11.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.