First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <=2.2.2 | |
Apple iOS and macOS | <=10.12.1 | |
iPhone OS | <=10.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7657 is considered a critical vulnerability as it allows unauthorized access to sensitive information from kernel memory.
To fix CVE-2016-7657, update your affected Apple devices to the latest versions of iOS, macOS, or watchOS.
CVE-2016-7657 affects iOS versions before 10.2, macOS versions before 10.12.2, and watchOS versions before 3.1.3.
CVE-2016-7657 involves the "IOKit" component which is responsible for interacting with hardware in Apple devices.
CVE-2016-7657 can potentially be exploited through a crafted application that targets the security vulnerability.