Vulnerability record · CVE-2016-4657 · published 25 August 2016
CVE-2016-4657: Apple iOS WebKit out-of-bounds write enables remote code execution
Apple · Iphone Os
WebKit in Apple iOS before 9.3.5 contains an out-of-bounds write (CWE-787) that lets a crafted web site corrupt memory and execute arbitrary code or crash the browser. Because the flaw sits in the rendering engine reached by ordinary web browsing, it is a potent remote attack vector against unpatched iPhones and iPads.
Description
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely reachable via browsing, has public exploit code, is in CISA KEV, and carries a very high EPSS score, though exploitation requires user interaction and the affected iOS versions are now old.
What it is
WebKit in Apple iOS before 9.3.5 contains an out-of-bounds write (CWE-787) that lets a crafted web site corrupt memory and execute arbitrary code or crash the browser. Because the flaw sits in the rendering engine reached by ordinary web browsing, it is a potent remote attack vector against unpatched iPhones and iPads.
Impact
An attacker who gets the victim to load a malicious page can run arbitrary code in the WebKit process, potentially leading to full device compromise, or cause a denial of service.
Attack surface
Reached over the network when the user visits a crafted web site; no authentication is required but user interaction (loading the page) is needed, per the CVSS vector AV:N/AC:L/PR:N/UI:R.
Exploitation
CVE-2016-4657 is listed in CISA KEV (added 2022-05-24) and has a high EPSS 30-day probability of roughly 0.67 (99th percentile); public exploit references exist, including an Exploit-DB entry and a video, and the flaw was linked to the Pegasus/Trident campaign.
What to do
- Update iOS to 9.3.5 or later per Apple's advisory (HT207107); this is the only complete fix.
- Inventory and prioritize any remaining iOS devices below 9.3.5, especially those in high-risk roles.
- Restrict or monitor web browsing on unpatched devices and block known malicious domains where feasible.
- Treat unpatched devices as compromised if they may have been exposed to targeted web content and consider device reset.
- Track KEV remediation deadlines and verify patching through MDM or asset reporting.
Detection
- Monitor for Safari/WebKit crashes or unexpected process terminations on iOS devices, which can indicate memory corruption attempts.
- Hunt for devices reporting iOS versions below 9.3.5 in MDM or asset inventory.
- Review network or proxy logs for connections to known exploit or Pegasus-related infrastructure.
- Watch for anomalous outbound traffic or process behavior from mobile devices that visited suspicious sites.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-4657 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "Apple iOS Webkit Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-4657 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-4657), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.