CVE-2016-4734 is a critical memory corruption vulnerability in WebKit affecting Apple iOS before version 10, Safari before version 10, and tvOS before version 10. This flaw allows remote attackers to execute arbitrary code or cause a denial of service simply by enticing a user to visit a crafted website. With a CVSSv3 score of 9.6 (CRITICAL), this vulnerability has a network-based attack vector, low attack complexity, and requires user interaction, but can lead to high impacts on confidentiality, integrity, and availability. The EPSS score and FAUCET Risk Score indicate a significant potential for exploitation. Despite its high severity, there is no evidence of active exploitation (not in KEV), nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting it has not garnered significant public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 10.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.0CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.