Information disclosure in Apple iOS - CVE-2016-4680

 

Information disclosure in Apple iOS - CVE-2016-4680

Published: October 26, 2016


Vulnerability identifier: #VU1072
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4680
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to obtain potentially sensitive information on the target system.
The weakness exists due to improper input validation. A specially crafted application lets attackers access kernel memory.
Successfull exploitation of the vulnerability results in disclosure of important data on the vulnerable system.

Affected software

Apple iOS

How to mitigate CVE-2016-4680

Update to version 10.1.


External References

Related Security Bulletins