Junglewise Threat Intelligence

CVE-2016-4656: Apple iOS Memory Corruption Vulnerability

CVE-2016-4656 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-24

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

A memory corruption vulnerability (specifically an out-of-bounds write) in the Apple iOS kernel allows a crafted application to execute arbitrary code with elevated privileges or cause a denial of service. This vulnerability was notably used as part of the 'Trident' exploit chain.

Affected products

  • Apple iOS before 9.3.5

Timeline

  • 2016-08-25: disclosed: Public disclosure of Trident/Pegasus exploit chain by Lookout and Citizen Lab.
  • 2016-08-25: patched: Apple released iOS 9.3.5 to address the vulnerability.
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • exploited: Reported as exploited in the wild as part of the Pegasus spyware attacks.

Related threats