High severity7.8NVD Advisory· Published May 20, 2016· Updated May 6, 2026
CVE-2016-1823
CVE-2016-1823
Description
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a different vulnerability than CVE-2016-1824.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- bugs.chromium.org/p/project-zero/issues/detailnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/39927/nvdExploitThird Party AdvisoryVDB Entry
- lists.apple.com/archives/security-announce/2016/May/msg00001.htmlnvdMailing ListVendor Advisory
- lists.apple.com/archives/security-announce/2016/May/msg00002.htmlnvdMailing ListVendor Advisory
- lists.apple.com/archives/security-announce/2016/May/msg00003.htmlnvdMailing ListVendor Advisory
- lists.apple.com/archives/security-announce/2016/May/msg00004.htmlnvdMailing ListVendor Advisory
- packetstormsecurity.com/files/137397/OS-X-Kernel-Raw-Cast-Out-Of-Bounds-Read.htmlnvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/90698nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1035890nvdThird Party AdvisoryVDB Entry
- support.apple.com/HT206564nvdVendor Advisory
- support.apple.com/HT206566nvdVendor Advisory
- support.apple.com/HT206567nvdVendor Advisory
- support.apple.com/HT206568nvdVendor Advisory
News mentions
0No linked articles in our index yet.