VulnerabilityModified
CVE-2016-7591
It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
MEDIUM 6.5EPSS 1.36%
Does this matter?
Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- apple/iphone os · apple/mac os x · apple/watchos
- Source
- product-security@apple.com
References
- http://www.securityfocus.com/bid/94905Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037469
- https://support.apple.com/HT207422Vendor Advisory
- https://support.apple.com/HT207423Vendor Advisory
- https://support.apple.com/HT207487Vendor Advisory
- http://www.securityfocus.com/bid/94905Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037469
- https://support.apple.com/HT207422Vendor Advisory
- https://support.apple.com/HT207423Vendor Advisory
- https://support.apple.com/HT207487Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.