First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=10.1.1 | |
macOS Yosemite | <=10.12.1 | |
watchOS | <=2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4691 is considered a critical vulnerability that allows attackers to execute arbitrary code on affected Apple devices.
To fix CVE-2016-4691, users need to update their devices to the latest versions of iOS, macOS, or watchOS provided by Apple.
CVE-2016-4691 affects iOS versions prior to 10.2, macOS versions prior to 10.12.2, and watchOS versions prior to 3.1.3.
The vulnerability arises from the "FontParser" component in the affected Apple operating systems.
Yes, CVE-2016-4691 can cause a denial of service due to memory corruption in the vulnerable components.