First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10 is affected. Safari before 10 is affected. iTunes before 12.5.1 is affected. tvOS before 10 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes | <=12.5 | |
Apple iPhone OS | <=9.3.5 | |
Apple Safari | <=9.1.3 | |
tvOS | <=9.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4764 has a high severity rating, allowing attackers to execute arbitrary code remotely.
To fix CVE-2016-4764, update to the latest versions of iOS, Safari, iTunes, or tvOS that address the vulnerability.
CVE-2016-4764 affects iOS versions before 10, Safari versions before 10, iTunes versions before 12.5.1, and tvOS versions before 10.
CVE-2016-4764 involves the WebKit component, which is responsible for rendering web content.
Yes, CVE-2016-4764 can allow remote attackers to cause a denial of service.