CVE-2016-1819 is a use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method affecting Apple iOS, OS X, tvOS, and watchOS. This flaw allows a crafted app to execute arbitrary code in a privileged context or cause a denial of service due to memory corruption. With a CVSS v3 score of 7.8 (High), it has a local attack vector, low attack complexity, and high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog or currently on the Hot List, exploit code for a related kernel use-after-free in IOAcceleratorFamily2 exists on ExploitDB. There is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 9.3.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.11.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 2.2.1CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.