PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-7645 Apple CVE debrief

CVE-2016-7645 describes an Apple WebKit memory-corruption issue that can be triggered by a crafted website, with potential outcomes including arbitrary code execution or a denial of service. The supplied NVD data maps impact to iOS before 10.2, Safari before 10.0.2, iCloud before 6.1, and iTunes before 12.5.4. Apple vendor advisory links are included in the record as the primary remediation references.

Vendor
Apple
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-20
Original CVE updated
2026-05-13
Advisory published
2017-02-20
Advisory updated
2026-05-13

Who should care

Users and administrators of Apple devices and software running iOS, Safari, iCloud, or iTunes versions below the fixed releases, especially systems that regularly browse untrusted or externally supplied web content.

Technical summary

NVD classifies this issue as CWE-119 and gives it a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerable component is WebKit, and the attack requires user interaction with a crafted website, which can lead to memory corruption, application crash, or arbitrary code execution.

Defensive priority

High — network-reachable, user-assisted web exposure with high confidentiality, integrity, and availability impact across multiple Apple products.

Recommended defensive actions

  • Update affected Apple products to the fixed versions or later: iOS 10.2, Safari 10.0.2, iCloud 6.1, and iTunes 12.5.4.
  • Prioritize patching systems that are used to browse the web or open untrusted content.
  • Use the Apple vendor advisory links in the record to confirm the relevant product-specific fixes.
  • Validate fleet exposure by comparing installed versions against the NVD CPE ranges in the supplied record.

Evidence notes

The supplied NVD record identifies the vulnerable Apple CPEs and lists the affected version ceilings for iPhone OS, Safari, iCloud, and iTunes. It also records the WebKit component, a CWE-119 weakness, and the CVSS vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Apple support links are included as vendor advisories in the source corpus, while the record shows no supplied KEV listing or ransomware association. CVE published time is 2017-02-20 and the NVD record was last modified on 2026-05-13.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-7645 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-7645

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-7645 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7645

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.