These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2016-7626 describes a memory-corruption flaw in Apple’s Profiles component that could be triggered remotely with a crafted certificate profile. The reported impact includes arbitrary code execution or a denial of service through an application crash. NVD lists the issue as High severity with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Apple’s affected versions in the supplied corpus are iOS b [truncated]
CVE-2016-7625 is a low-severity local information-disclosure issue in Apple macOS before 10.12.2. According to the NVD record, the flaw is in the IOKit component and can allow a local user to obtain sensitive kernel memory-layout information through unspecified vectors. The issue was published on 2017-02-20 and is associated with CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
CVE-2016-7624 is a local information disclosure issue in Apple macOS before 10.12.2 involving the IOAcceleratorFamily component. According to the source record, a local user could obtain sensitive kernel memory-layout information through unspecified vectors. NVD classifies the issue as CWE-200 and rates it low severity.
CVE-2016-7623 is an Apple WebKit information-disclosure issue that can be triggered from a website. According to the CVE description, remote attackers could obtain sensitive information via a blob URL. The NVD record maps the issue to Apple iPhone OS and Safari, with confidentiality impact only and no integrity or availability impact. This is a browser-facing flaw, so exposure depends on users visiting a [truncated]
CVE-2016-7622 is a Grapher component vulnerability in Apple macOS that affects versions before 10.12.2. According to the supplied record, a crafted .gcx file can trigger memory corruption in Grapher, which may lead to an application crash or arbitrary code execution. The official NVD record also maps the issue to high impact with user interaction required, so the main risk is a malicious file being opened [truncated]
CVE-2016-7621 is a kernel use-after-free issue in older Apple operating-system releases. According to the CVE description, it can let a local user execute arbitrary code in a privileged context or trigger a denial of service. The record is rated High severity, and the supplied data does not show a Known Exploited Vulnerabilities listing.
CVE-2016-7620 is a low-severity information disclosure issue in Apple’s IOSurface component affecting macOS before 10.12.2. According to the NVD record and Apple’s advisory reference, a local user could obtain sensitive kernel memory-layout information through unspecified vectors. The main security concern is that this leaks internal address-layout details rather than directly affecting integrity or availability.
CVE-2016-7619 is a local Apple libarchive vulnerability tied to symlink handling. The NVD record rates it medium severity and indicates that a low-privilege local attacker could write to arbitrary files, creating an integrity-impact issue on affected Apple systems. Apple’s advisory links cover the affected iOS, macOS, and watchOS release lines for remediation.
CVE-2016-7618 is a high-severity Apple macOS issue in the Foundation component that was fixed in macOS 10.12.2 and earlier affected versions up to 10.12.1. A specially crafted .gcx file can trigger memory corruption, leading to an application crash or potentially arbitrary code execution. Because exploitation depends on file handling and user interaction, organizations should prioritize patching systems t [truncated]
CVE-2016-7617 is a high-severity Apple macOS Bluetooth issue disclosed on 2017-02-20. According to the NVD record, macOS before 10.12.2 is affected, with the vulnerable range mapped through 10.12.1. The flaw is described as a type confusion issue in the Bluetooth component that can let a crafted app trigger arbitrary code execution in a privileged context or cause a denial of service. From a defender’s pe [truncated]
CVE-2016-7616 is a high-severity Apple vulnerability in the Disk Images component. According to the published record, a crafted app can trigger memory corruption that may lead to arbitrary code execution in a privileged context or cause a denial of service. The issue affects older Apple OS releases across iOS, macOS, and watchOS, and should be treated as a patch-priority endpoint issue for any environment [truncated]
CVE-2016-7615 is an Apple Kernel denial-of-service issue affecting older iOS, macOS, and watchOS releases. The supplied NVD record describes local exploitation by a user with limited privileges and rates the issue as medium severity because the impact is availability-only and can terminate or disrupt the system. This is a patch-priority item for organizations that still support affected Apple versions, es [truncated]
CVE-2016-7614 describes a local information-disclosure issue in Apple iCloud for Windows. The flaw can let a local user obtain sensitive information from the iCloud desktop-client process memory through unspecified vectors. NVD lists the affected iCloud line as versions through 6.0.1, while the CVE description states iCloud before 6.1; in practice, defenders should rely on the vendor advisory and confirm [truncated]
CVE-2016-7613 describes a kernel component flaw in certain Apple products where a crafted app could trigger object-lifetime mishandling during process spawning and execute arbitrary code in a privileged context. Apple and NVD list affected releases across iOS, macOS, tvOS, and watchOS, with the issue publicly disclosed on 2017-02-20.
CVE-2016-7612 is an Apple kernel memory-corruption issue that could let a crafted app execute code in a privileged context or trigger a denial of service. Apple addressed it in iOS 10.2, macOS 10.12.2, and watchOS 3.1.3. The NVD record rates the issue High severity with a CVSS 3.0 score of 7.8, reflecting the potential impact on confidentiality, integrity, and availability.
CVE-2016-7611 is a high-severity Apple WebKit memory corruption issue that can let a remote attacker execute arbitrary code or crash the affected app when a user visits a crafted website. The supplied corpus ties the issue to multiple Apple products, including iOS, Safari, iCloud, and iTunes, and shows official Apple-linked remediation references in NVD. Because exploitation requires user interaction, the [truncated]
CVE-2016-7610 is a high-severity Apple WebKit memory-corruption issue that can be triggered by a crafted website. The record says it can lead to arbitrary code execution or a denial of service (application crash), and NVD rates it 8.8/High. Because the attack vector is network-based and requires user interaction, systems that browse untrusted web content are the main concern.
CVE-2016-7609 is a local denial-of-service issue in Apple’s AppleGraphicsPowerManagement component on macOS versions before 10.12.2. According to the CVE record and NVD metadata, the flaw is a NULL pointer dereference that can be triggered by a local user, causing an availability impact without any indicated confidentiality or integrity impact.
CVE-2016-7608 is a macOS information disclosure issue in Apple’s IOFireWireFamily component. According to NVD and Apple’s advisory reference, macOS versions before 10.12.2 are affected, and a local user could obtain sensitive information from kernel memory through unspecified vectors. The issue is rated medium severity and aligns with CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
CVE-2016-7607 is an Apple kernel information disclosure issue affecting iOS, macOS, and watchOS versions identified in the CVE record. A crafted app could expose sensitive information from kernel memory, making this a confidentiality-focused flaw with medium severity.
CVE-2016-7606 is a kernel memory-corruption issue in Apple products that can let a crafted app trigger arbitrary code execution in a privileged context or cause a denial of service. The CVE description identifies affected releases as iOS before 10.2, macOS before 10.12.2, and watchOS before 3.1.3. The supplied NVD record rates the issue High with CVSS 7.8 and a local, user-interaction-required attack vector.
CVE-2016-7605 is a macOS Bluetooth issue that can let a crafted app trigger a NULL pointer dereference and crash affected systems. NVD lists macOS X versions through 10.12.1 as vulnerable, and the issue was publicly disclosed on 2017-02-20. The impact is availability-only denial of service, with local attack conditions and user interaction required.
CVE-2016-7604 is a macOS issue in Apple’s CoreCapture component that can let a local user cause a denial of service through a null pointer dereference. NVD lists affected systems as macOS versions through 10.12.1, and Apple’s advisory addresses the issue in macOS 10.12.2. The published CVSS vector indicates local attack requirements with no confidentiality or integrity impact, but high availability impact.
CVE-2016-7603 is a local denial-of-service vulnerability in Apple’s CoreStorage component affecting macOS versions before 10.12.2. According to the official CVE/NVD record, the issue can be triggered by a local user and results in a NULL pointer dereference, with availability impact but no documented confidentiality or integrity impact in the supplied sources. Apple’s advisory is referenced by NVD as the [truncated]
CVE-2016-7602 is a macOS vulnerability in Apple’s Intel Graphics Driver component. According to the published record, systems running macOS before 10.12.2 are affected. A crafted app can trigger memory corruption, which may allow arbitrary code execution in a privileged context or cause a denial of service.
CVE-2016-7601 is an Apple iOS issue in the Local Authentication component that could fail to honor the configured screen-lock time interval while a Touch ID prompt was visible. NVD lists affected iPhone OS versions through 10.1.1, and Apple’s advisory is referenced in the record.
CVE-2016-7600 is a macOS information-disclosure issue in Apple’s OpenPAM component. According to the NVD record, macOS before 10.12.2 is affected, and the flaw can allow a local attacker to obtain sensitive information when failed PAM authentication is mishandled by a sandboxed app. The published CVSS 3.0 vector indicates local access, no user interaction, and confidentiality impact only.
CVE-2016-7599 is an Apple WebKit information-disclosure issue that was published on 2017-02-20. According to the NVD record, a crafted website using HTTP redirects could allow remote attackers to bypass the Same Origin Policy and obtain sensitive information. NVD marks the issue as medium severity with CVSS 6.5 and a network-reachable, user-interaction-required attack profile.
CVE-2016-7598 is an Apple WebKit information-disclosure issue that can let a remote attacker obtain sensitive data from process memory through a crafted website. The CVE affects multiple Apple products, including iOS, Safari, iCloud, and iTunes, with vendor advisories published for the fixes. Because exploitation requires user interaction and the impact is confidentiality-only, the main risk is exposure o [truncated]
CVE-2016-7597 is a medium-severity Apple iOS issue affecting SpringBoard. The supplied CVE description says physically proximate attackers could maintain the unlocked state through Handoff and Siri-related vectors on iOS before 10.2. NVD’s affected CPE entry lists iPhone OS through 10.1.1, so defenders should treat this as a pre-10.2 lock-state issue and verify fleet versions against the vendor advisory.