Junglewise Threat Intelligence

CVE-2016-4655: Apple iOS Information Disclosure Vulnerability

CVE-2016-4655 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2022-05-24

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

The kernel in Apple iOS before 9.3.5 allows local attackers to obtain sensitive information from memory via a crafted application. This vulnerability was part of the 'Trident' exploit chain used in the Pegasus spyware.

Affected products

  • Apple iOS before 9.3.5

Timeline

  • 2016-08-25: disclosed: Public disclosure of Trident/Pegasus exploits by Lookout
  • 2016-08-25: patched: Apple released iOS 9.3.5 to address the vulnerability
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-24: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats