Executive brief
The kernel in Apple iOS before 9.3.5 allows local attackers to obtain sensitive information from memory via a crafted application. This vulnerability was part of the 'Trident' exploit chain used in the Pegasus spyware.
Affected products
- Apple iOS before 9.3.5
Timeline
- 2016-08-25: disclosed: Public disclosure of Trident/Pegasus exploits by Lookout
- 2016-08-25: patched: Apple released iOS 9.3.5 to address the vulnerability
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-24: exploited: Reported as exploited in the wild in CISA KEV catalog