CVE-2016-4655Patch(apple / iphone_os)

LOWCVSS 5.5 · MEDIUMCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple iphone_os systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-06-14. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iphone_os

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
iphone_os

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-13: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-02-28: 102-2803-0103-13
Signal classification3 categories
Patch
133.3%
General
133.3%
PoC
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-281
Patch1
2026-03-011
General1
2026-03-131
PoC1
Full discourse3 posts
  • Hermes Tool@Hermes_tooll
    PoC

    Exploiting CVE-2016-4655 - Create Your Own iOS Jailbreak [Part 1] | Kern... https://youtu.be/4y8vMm4TINs via

    Post summary

    A video demonstrates how to exploit CVE‑2016‑4655 to jailbreak an iOS device, serving as a proof‑of‑concept for the vulnerability.

    08038225.2K
    2.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-0625 2 - CVE-2016-4655 3 - CVE-2025-27363 4 - CVE-2026-28515 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple list of five trending CVEs with no additional context or details.

    00010267
    1.7K followersView on X
  • Grok@grok
    Patch

    Pegasus (NSO) uses targeted zero-day chains, often zero-click via iMessage: - 2016 Trident: CVE-2016-4655 (kernel leak), -4656 (kernel corruption/jailbreak), -4657 (WebKit). SMS link (one-click). - 2021 FORCEDENTRY (CVE-2021-30860): Integer overflow in CoreGraphics JBIG2 PDF parser (disguised as GIF in iMessage). Turing-complete logic via refinement ops. - 2022: 3 zero-click chains—PWNYOURHOME (HomeKit + iMessage PNG), FINDMYPWN/LATENTIMAGE (Find My + iMessage). - 2023: WebP heap overflow (CVE-2023-4863/-41064) via images. - 2025+: WebKit/kernel zero-days (e.g. CVE-2025-43529/-14174). Patched fast by Apple; update + Lockdown Mode mitigates.

    Post summary

    The post enumerates several CVEs exploited by Pegasus, details their technical nature, and notes that Apple promptly patched them with updates and Lockdown Mode.

    00001126
    8.3M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleiphone_os---
OSappleiphone_os10.0--

Explore more