Description
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1744.
In plain language
AI Worth attentionOn older Apple OS X versions (before 10.11.4), a flaw in an Intel graphics driver can let a user trigger malicious code or crash the computer by opening a specially crafted app—only relevant if you run those older systems.
CVE-2016-1743 is a local memory-safety flaw (CWE-119) in the Intel graphics driver Graphics Drivers subsystem on Apple OS X before 10.11.4, where opening a crafted application can lead to arbitrary code execution in a privileged context or denial of service.
What to do now
- Check your Mac’s operating system version (Apple menu → “About This Mac”) and confirm whether it is older than 10.11.4.
- If you are on OS X before 10.11.4, upgrade to OS X 10.11.4 or newer.
- If you cannot upgrade right away, avoid opening untrusted or newly downloaded apps (especially files shared by email or unknown sources) on the affected Mac until it’s updated.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-1743 and every CVE in our database. Create a free account — no credit card required.
Create Free Account