Executive brief
WebKit in Apple iOS contains a memory corruption vulnerability (out-of-bounds write) that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website. This vulnerability was famously exploited as part of the 'Trident' exploit chain used by the Pegasus spyware.
Affected products
- Apple iOS before 9.3.5
- Apple WebKit before 9.3.5
Timeline
- 2016-08-25: disclosed: Public disclosure of Trident/Pegasus exploit chain.
- 2016-08-25: patched: Apple released iOS 9.3.5 to address the vulnerability.
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2016-08-25: exploited: Reported as exploited in the wild by Lookout/Citizen Lab.