Description
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1828, CVE-2016-1829, and CVE-2016-1830.
In plain language
AI Worth attentionThis iOS/macOS/tvOS/watchOS kernel bug could let a malicious app crash the device or possibly run code with high privileges on older versions, so you should upgrade if you’re still using those versions.
CVE-2016-1827 is a memory-corruption kernel vulnerability (CWE-119) in Apple iOS/OS X/macOS, tvOS, and watchOS versions prior to the fixed releases; it can be triggered via a crafted app to execute code in a privileged context or cause denial of service.
What to do now
- Check which Apple OS versions your business devices are running (iPhone/iPad on iOS, Macs on macOS/OS X, Apple TV on tvOS, Apple Watch on watchOS).
- Update iPhone/iPad to iOS 9.3.2 or later.
- Update Mac computers to 10.11.5 or later.
- Update Apple TV to tvOS 9.2.1 or later.
- Update Apple Watch to watchOS 2.2.1 or later.
- If you cannot upgrade immediately, limit use of untrusted apps on affected devices until you can patch.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-1827 and every CVE in our database. Create a free account — no credit card required.
Create Free Account