Description
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.
In plain language
AI Worth attentionThis is a vulnerability in older Apple mobile/desktop operating systems where a specially crafted app could crash the device or potentially run code with high privileges; small businesses should update if they’re still using iOS < 9.3, OS X < 10.11.4, tvOS < 9.2, or watchOS < 2.2.
CVE-2016-1755 is a kernel memory-corruption flaw in Apple iOS/OS X/tvOS/watchOS that can be triggered by a crafted app, potentially leading to privileged code execution or denial of service on vulnerable versions.
What to do now
- Check each device’s OS version (iOS, macOS/OS X, tvOS, watchOS) and confirm whether it is older than iOS 9.3, OS X 10.11.4, tvOS 9.2, or watchOS 2.2.
- Upgrade any affected devices to the fixed versions: iOS 9.3 or newer, OS X 10.11.4 or newer, tvOS 9.2 or newer, or watchOS 2.2 or newer.
- If you cannot update immediately, avoid installing or opening untrusted apps until you upgrade, since the issue is triggered by a crafted app.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-1755 and every CVE in our database. Create a free account — no credit card required.
Create Free Account