936
VMScore

CVE-2016-1828

Published: 20/05/2016 Updated: 25/03/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 936
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The kernel in Apple iOS prior to 9.3.2, OS X prior to 10.11.5, tvOS prior to 9.2.1, and watchOS prior to 2.2.1 allows malicious users to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple mac os x

apple tvos

apple watchos

Exploits

## rootsh rootsh is a local privilege escalation targeting OS X Yosemite 10105 build 14F27 It exploits [CVE-2016-1758] and [CVE-2016-1828], two vulnerabilities in XNU that were patched in OS X El Capitan [10114] and [10115] rootsh will not work on platforms with SMAP enabled [CVE-2016-1758]: wwwcvemitreorg/cgi-bin/cvenamecgi? ...

Github Repositories

Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.

bazad5 Local privilege escalation for OS X 10105 via CVE-2016-1828

Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.

bazad5 Local privilege escalation for OS X 10105 via CVE-2016-1828

A collection of resources for OSX/iOS reverse engineering.

osx & ios re 101 Work in progress as I am actively collecting these Must read reverseputas/ blogpaloaltonetworkscom/tag/mac-os-x/ wwwsynackcom/blog/r-d-projects/os-x-security-research/ pewpewthespellscom/rehtml githubcom/bx/machO-tools githubcom/kpwn/iOSRE Keep these handy "OSX Mach-O File Format Referen

A curated list of not properly fixed apple security bugs and attempts to influence disclosure

bad-bad-apple A curated list of not properly fixed apple security bugs and attempts to influence disclosure This list will be filled over the next weeks with instances that we know of TODO All vulnerabilities require description, link to original source - writeups/talks/ Insufficiently patched iOS vulnerabilities The following table is work in progress It shows for every i

Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.

rootsh rootsh is a local privilege escalation targeting OS X Yosemite 10105 build 14F27 It exploits CVE-2016-1758 and CVE-2016-1828, two vulnerabilities in XNU that were patched in OS X El Capitan 10114 and 10115 rootsh will not work on platforms with SMAP enabled CVE-2016-1758 CVE-2016-1758 is an information leak caused by copying out uninitialized bytes of kernel sta