CVE-2016-4701

medium
Published 2016-09-25 · Modified 2026-05-06
CVSS v3
6.2
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
2.1
VIR risk
6.2

Description

Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.

Predictions

Exploit likelihood
62%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: product-security@apple.com — https://support.apple.com/HT207170

OS impact

OSVersionStatusFixed in
macos macosaffected

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.