PatchSiren cyber security CVE debrief
CVE-2016-7602 Apple CVE debrief
CVE-2016-7602 is a macOS vulnerability in Apple’s Intel Graphics Driver component. According to the published record, systems running macOS before 10.12.2 are affected. A crafted app can trigger memory corruption, which may allow arbitrary code execution in a privileged context or cause a denial of service.
- Vendor
- Apple
- Product
- CVE-2016-7602
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Apple Mac administrators, endpoint security teams, and users running macOS versions earlier than 10.12.2 should prioritize this issue, especially on systems that may run untrusted or third-party applications.
Technical summary
The NVD record identifies a memory corruption weakness (CWE-119) in the Intel Graphics Driver on macOS. The affected range in the source data extends through macOS 10.12.1, with Apple’s advisory referenced by NVD. The CVSS vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates local exploitation that requires user interaction but can have high impact, including privileged code execution or denial of service.
Defensive priority
High. The combination of high-impact consequences and a well-defined affected version range makes patch verification and version inventory important for Apple environments that still contain pre-10.12.2 systems.
Recommended defensive actions
- Update affected Macs to macOS 10.12.2 or later.
- Inventory devices to identify any systems still running macOS 10.12.1 or earlier.
- Verify patch status on managed endpoints after remediation.
- Restrict untrusted application execution where practical, especially on legacy systems.
- Monitor Apple security advisories and vendor maintenance windows for similar graphics-driver fixes.
Evidence notes
Source data from NVD states the issue affects macOS before 10.12.2 and maps the vulnerable CPE range through 10.12.1. The record also cites CWE-119 and references Apple’s vendor advisory (HT207423) along with third-party advisory entries. The CVE was published on 2017-02-20 and later modified on 2026-05-13; those dates describe the record timeline, not the original flaw occurrence.
Official resources
-
CVE-2016-7602 CVE record
CVE.org
-
CVE-2016-7602 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
- Source reference
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
CVE record published 2017-02-20 and modified 2026-05-13. NVD references Apple’s vendor advisory HT207423 and third-party advisories for this issue.