CVE-2016-7626 is a critical memory corruption vulnerability affecting Apple iOS before 10.2, tvOS before 10.1, and watchOS before 3.1.1, specifically within the "Profiles" component. It allows remote attackers to execute arbitrary code or cause a denial of service through a crafted certificate profile. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable via a network-based attack requiring user interaction, leading to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an exploit (EDB-40906) is publicly available, and it has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 3.1.1CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.