CVE-2016-1719
Description
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
✚ Propose a mitigation on Community → Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
iOS Kernel - IOReportHub Use-After-Free
iOS Kernel - AppleOscarAccelerometer Use-After-Free
iOS Kernel - AppleOscarCMA Use-After-Free
iOS Kernel - AppleOscarCompass Use-After-Free
iOS Kernel - AppleOscarGyro Use-After-Free
Source: https://code.google.com/p/google-security-research/issues/detail?id=608
Panic log attached
OS X advisory: https://support.apple.com/en-us/HT205731
iOS advisory: https://support.apple.com/en-us/HT205732
Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39359.zip
iOS Kernel - IOHIDEventService Use-After-Free
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | affected | |
References
- http://lists.apple.com/archives/security-announce/2016/Jan/msg00002.html
- http://lists.apple.com/archives/security-announce/2016/Jan/msg00003.html
- http://lists.apple.com/archives/security-announce/2016/Jan/msg00005.html
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html
- http://packetstormsecurity.com/files/135438/iOS-Kernel-IOReportHub-Use-After-Free.html
- http://packetstormsecurity.com/files/135439/iOS-Kernel-IOHIDEventService-Use-After-Free.html
- http://packetstormsecurity.com/files/135440/iOS-Kernel-AppleOscarCMA-Use-After-Free.html
- http://packetstormsecurity.com/files/135441/iOS-Kernel-AppleOscarCompass-Use-After-Free.html
- http://packetstormsecurity.com/files/135442/iOS-Kernel-AppleOscarAccelerometer-Use-After-Free.html
- http://packetstormsecurity.com/files/135443/iOS-Kernel-AppleOscarGyro-Use-After-Free.html
- http://www.securitytracker.com/id/1034736
- https://code.google.com/p/google-security-research/issues/detail?id=603
- https://code.google.com/p/google-security-research/issues/detail?id=604
- https://code.google.com/p/google-security-research/issues/detail?id=605
- https://code.google.com/p/google-security-research/issues/detail?id=606
- https://code.google.com/p/google-security-research/issues/detail?id=607
- https://code.google.com/p/google-security-research/issues/detail?id=608
- https://support.apple.com/HT205729
- https://support.apple.com/HT205731
- https://support.apple.com/HT205732
- https://support.apple.com/HT206168
- https://www.exploit-db.com/exploits/39359/
- https://www.exploit-db.com/exploits/39360/
- https://www.exploit-db.com/exploits/39361/
- https://www.exploit-db.com/exploits/39362/
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.