Description
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
In plain language
AI Worth attentionThis is a kernel flaw in older Apple iOS, macOS, and watchOS versions that can let a malicious app—if you trick a user into running it—take full control of the device or crash it. If you’re still on those older versions, you should act.
CVE-2016-7644 is a kernel use-after-free issue (CWE-416) in older Apple OS versions (iOS < 10.2, macOS < 10.12.2, watchOS < 3.1.3) that can be triggered by getting the user to run a crafted app, leading to full compromise of privileged device functionality or denial of service.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-7644 and every CVE in our database. Create a free account — no credit card required.
Create Free Account