PT-2016-2803 · Apple · Ios+4
Published
2016-09-25
·
Updated
2019-03-09
·
CVE-2016-4726
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IOAcceleratorFamily versions prior to iOS 10, OS X 10.12, tvOS 10, and watchOS 3
Description
The issue allows attackers to execute arbitrary code in a privileged context or cause a denial of service due to memory corruption via a crafted app. It is caused by a buffer overflow in the IOAcceleratorFamily component of the operating systems, which can be exploited by a remote attacker to achieve the aforementioned effects.
Recommendations
For versions prior to iOS 10, update to iOS 10 or later.
For versions prior to OS X 10.12, update to OS X 10.12 or later.
For versions prior to tvOS 10, update to tvOS 10 or later.
For versions prior to watchOS 3, update to watchOS 3 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ioacceleratorfamily
Os X
Ios
Tvos
Watchos