Junglewise Threat Intelligence

CVE-2016-4657: Apple iOS Webkit Memory Corruption Vulnerability

CVE-2016-4657 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-24

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

WebKit in Apple iOS contains a memory corruption vulnerability (out-of-bounds write) that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website. This vulnerability was famously exploited as part of the 'Trident' exploit chain used by the Pegasus spyware.

Affected products

  • Apple iOS before 9.3.5
  • Apple WebKit before 9.3.5

Timeline

  • 2016-08-25: disclosed: Public disclosure of Trident/Pegasus exploit chain.
  • 2016-08-25: patched: Apple released iOS 9.3.5 to address the vulnerability.
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2016-08-25: exploited: Reported as exploited in the wild by Lookout/Citizen Lab.

Related threats