PatchSiren cyber security CVE debrief
CVE-2016-7667 Apple CVE debrief
CVE-2016-7667 is an Apple CoreText issue that can be triggered remotely with a crafted string and result in denial of service. The CVE description states that iOS before 10.2 and macOS before 10.12.2 are affected, while the NVD record maps vulnerable CPE ranges to iPhone OS through 10.1.1 and macOS through 10.12.1. Apple vendor advisories are referenced by NVD, and the issue was published on 2017-02-20. The practical defensive takeaway is straightforward: install the Apple security updates that move impacted devices to the fixed releases.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-20
- Advisory updated
- 2026-05-13
Who should care
Apple device administrators, endpoint security teams, and anyone responsible for iPhone/iPad or macOS fleets should care most. Because the issue is network-reachable and requires no privileges or user interaction, systems that process untrusted content or are broadly exposed should be prioritized for patching.
Technical summary
The vulnerable component is CoreText, Apple’s text handling subsystem. According to the supplied CVE description, a crafted string can cause a remote denial of service on affected Apple platforms. NVD classifies the weakness as CWE-20 (improper input validation) and rates the attack vector as network-based with low complexity, no privileges required, no user interaction, and high availability impact (CVSS 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Defensive priority
High. The issue is remotely triggerable, needs no authentication or user interaction, and can disrupt availability on affected Apple devices, so remediation should be prioritized in normal patch cycles and accelerated for exposed or mission-critical fleets.
Recommended defensive actions
- Update iOS devices to 10.2 or later.
- Update macOS devices to 10.12.2 or later.
- Verify fleet inventory to find devices still on affected Apple releases.
- Use Apple vendor advisories HT207422 and HT207423 to confirm the applicable fixed builds for your environment.
- Treat the NVD version mapping as advisory metadata and validate remediation scope against Apple’s official guidance.
Evidence notes
Evidence is limited to the supplied CVE description, NVD metadata, and Apple vendor-advisory references listed in NVD. The CVE description identifies CoreText, remote denial of service, and the affected version ceilings. NVD adds the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and CWE-20. The record was originally published on 2017-02-20; the later 2026-05-13 modified timestamp reflects metadata updates, not the disclosure date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7667 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7667
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7667 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7667
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207422
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://support.apple.com/HT207423
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.