CVE-2016-4654 is a memory corruption vulnerability in IOMobileFrameBuffer affecting Apple iOS versions prior to 9.3.4. This high-severity vulnerability (CVSS 7.8) could allow an attacker to execute arbitrary code with elevated privileges or cause a denial of service through a specially crafted application, requiring user interaction. While not listed on the KEV catalog, its presence in a significant iOS update and mention by Team Pangu suggest it was a notable vulnerability at the time, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.3.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:9.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.