CVE-2016-1719

high
Published 2016-02-01 · Modified 2026-05-06
CVSS v3
7.8
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
8.8

Description

The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.

✚ Propose a mitigation on Community → Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-39364 dos ios verified
Google Security Research · 2016-01-28

iOS Kernel - IOReportHub Use-After-Free

Source code queued for fetch — refresh in a moment.
EDB-39360 dos ios verified
Google Security Research · 2016-01-28

iOS Kernel - AppleOscarAccelerometer Use-After-Free

Source code queued for fetch — refresh in a moment.
EDB-39362 dos ios verified
Google Security Research · 2016-01-28

iOS Kernel - AppleOscarCMA Use-After-Free

Source code queued for fetch — refresh in a moment.
EDB-39361 dos ios verified
Google Security Research · 2016-01-28

iOS Kernel - AppleOscarCompass Use-After-Free

Source code queued for fetch — refresh in a moment.
EDB-39359 dos ios verified text · 1 KB
Google Security Research · 2016-01-28

iOS Kernel - AppleOscarGyro Use-After-Free

text exploit Source: Exploit-DB
Source: https://code.google.com/p/google-security-research/issues/detail?id=608

Panic log attached

OS X advisory: https://support.apple.com/en-us/HT205731
iOS advisory: https://support.apple.com/en-us/HT205732

Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39359.zip
EDB-39363 dos ios verified
Google Security Research · 2016-01-28

iOS Kernel - IOHIDEventService Use-After-Free

Source code queued for fetch — refresh in a moment.

OS impact

OSVersionStatusFixed in
macos macosaffected

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.