PatchSiren cyber security CVE debrief
CVE-2016-7645 Apple CVE debrief
CVE-2016-7645 describes an Apple WebKit memory-corruption issue that can be triggered by a crafted website, with potential outcomes including arbitrary code execution or a denial of service. The supplied NVD data maps impact to iOS before 10.2, Safari before 10.0.2, iCloud before 6.1, and iTunes before 12.5.4. Apple vendor advisory links are included in the record as the primary remediation references.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Users and administrators of Apple devices and software running iOS, Safari, iCloud, or iTunes versions below the fixed releases, especially systems that regularly browse untrusted or externally supplied web content.
Technical summary
NVD classifies this issue as CWE-119 and gives it a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerable component is WebKit, and the attack requires user interaction with a crafted website, which can lead to memory corruption, application crash, or arbitrary code execution.
Defensive priority
High — network-reachable, user-assisted web exposure with high confidentiality, integrity, and availability impact across multiple Apple products.
Recommended defensive actions
- Update affected Apple products to the fixed versions or later: iOS 10.2, Safari 10.0.2, iCloud 6.1, and iTunes 12.5.4.
- Prioritize patching systems that are used to browse the web or open untrusted content.
- Use the Apple vendor advisory links in the record to confirm the relevant product-specific fixes.
- Validate fleet exposure by comparing installed versions against the NVD CPE ranges in the supplied record.
Evidence notes
The supplied NVD record identifies the vulnerable Apple CPEs and lists the affected version ceilings for iPhone OS, Safari, iCloud, and iTunes. It also records the WebKit component, a CWE-119 weakness, and the CVSS vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Apple support links are included as vendor advisories in the source corpus, while the record shows no supplied KEV listing or ransomware association. CVE published time is 2017-02-20 and the NVD record was last modified on 2026-05-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7645 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7645
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7645 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7645
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201706-15
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207421
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207422
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207424
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207427
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.