LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-4655: Apple iOS Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 24, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-4655 to its Known Exploited Vulnerabilities catalog on May 24, 2022, with a federal patch deadline of Jun 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

CVE-2016-4655 is an information-disclosure vulnerability in the Apple iOS kernel. A crafted application can cause the kernel to reveal sensitive data from memory. For IT and security teams managing iOS fleets, this matters because kernel-level leaks can expose credentials, tokens, or other process memory that attackers may use to escalate access or move laterally once a device is compromised.

Public detail is limited to the CWE-200 class and the CISA description; exact affected builds, CVSS scores, and exploit mechanics must be confirmed against the vendor advisory. CISA lists the required action as applying updates per vendor instructions. Ransomware use is not documented for this CVE.

How it works

The weakness is CWE-200: exposure of sensitive information to an unauthorized actor. In this case the Apple iOS kernel improperly handles certain requests from a malicious or crafted application, allowing that application to read memory contents that should remain isolated.

An attacker who can run code on the device—typically by tricking a user into installing an untrusted app or by abusing an existing foothold—crafts input that triggers the kernel path. The kernel then returns or leaks data from kernel or process memory. Because the flaw sits in the kernel, the leak can include material outside the attacker’s own process sandbox. No further exploit specifics are provided in the available facts; defenders should treat any untrusted application capable of exercising kernel interfaces as a potential vector and verify technical details in Apple’s advisory.

Am I affected? How to find it in your systems

Apple iOS runs on iPhone, iPad, and iPod touch devices. Enterprise environments commonly manage these through MDM, Apple Business Manager, or similar inventory tools.

How to remediate

Patch first. Apply the iOS updates that Apple released to address CVE-2016-4655, following the vendor’s instructions exactly. Use MDM to push the update, enforce minimum OS versions, and verify installation across the fleet.

After patching, harden the environment against the broader information-disclosure class:

If you can't patch immediately

When immediate updating is blocked by testing or operational constraints, reduce exposure with compensating controls:

These steps only buy time; they do not eliminate the kernel flaw. Schedule the official update as soon as validation completes.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data theft. If you suspect a crafted application exercised this kernel leak, treat the device as potentially breached: isolate it, capture a forensic image if policy requires, rotate any credentials or tokens that may have resided in memory, and review access logs for follow-on activity. Ransomware use is not documented for this CVE, but information disclosure can still enable other attacks. As a quick additional check, users can run a free exposure scan of their email addresses against known breach data sets to see whether related personal accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS
WeaknessCWE-200
Added to CISA KEVMay 24, 2022
Federal patch deadlineJun 14, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities