CVE-2016-1863 is a memory corruption vulnerability in the kernel of Apple iOS, OS X, tvOS, and watchOS, allowing a local attacker to gain privileges or cause a denial of service. This vulnerability has a CVSSv3 score of 7.8 (High), indicating that it is easily exploitable by a local attacker with low privileges and no user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While no active exploitation is noted in KEV, an ExploitDB entry (EDB-40652) exists for a use-after-free in IOBluetoothFamily.kext on OS X, suggesting proof-of-concept code is available. Despite this, the vulnerability has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.3.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.11.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 9.2.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 2.2.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.