Description
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.
In plain language
AI Worth attentionThis is a security weakness in older Apple mobile and desktop operating systems (iOS, OS X, tvOS, watchOS) that could let a crafted app crash or potentially run code with high privileges; if your devices are not updated to the fixed versions, you should act.
CVE-2016-1828 is a kernel memory-corruption weakness in Apple’s iOS/macOS (OS X), tvOS, and watchOS that can be triggered by a crafted app to cause denial of service or potential arbitrary code execution in a privileged context; fixed in iOS 9.3.2, OS X 10.11.5, tvOS 9.2.1, and watchOS 2.2.1.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-1828 and every CVE in our database. Create a free account — no credit card required.
Create Free Account