CVE-2016-4666 is a critical WebKit vulnerability affecting Apple iOS before 10.1, Safari before 10.0.1, and tvOS before 10.0.1, allowing remote attackers to execute arbitrary code or cause a denial of service through memory corruption via a crafted website. Rated 8.8 HIGH on CVSS, it has a low attack complexity and requires user interaction, but can lead to high confidentiality, integrity, and availability impacts. While there is no known public exploit code or active exploitation, it garnered some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.0.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 10.0.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.