First published: Fri May 20 2016(Updated: )
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1819.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.11.4 | |
Apple iPhone OS | <=9.3.1 | |
watchOS | <=2.2 | |
tvOS | <=9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1818 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2016-1818, ensure that your operating system is updated to at least iOS 9.3.2, macOS 10.11.5, tvOS 9.2.1, or watchOS 2.2.1.
CVE-2016-1818 affects Apple iOS versions prior to 9.3.2, OS X versions before 10.11.5, tvOS versions before 9.2.1, and watchOS versions before 2.2.1.
CVE-2016-1818 can enable attacks that lead to arbitrary code execution and denial of service due to memory corruption.
There is no official workaround for CVE-2016-1818; updating to the latest versions is the recommended approach.