VYPR
Low severity3.7NVD Advisory· Published Feb 20, 2017· Updated May 13, 2026

CVE-2016-7577

CVE-2016-7577

Description

Remote attackers can trigger memory corruption in FaceTime on iOS and macOS to obtain audio data from a call that appeared to have ended.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Remote attackers can trigger memory corruption in FaceTime on iOS and macOS to obtain audio data from a call that appeared to have ended.

Vulnerability

The vulnerability resides in the FaceTime component of iOS before version 10.1 and macOS before version 10.12.1. It allows remote attackers to trigger memory corruption, leading to the disclosure of audio data from a call that appeared to have ended. The exact code path is not detailed, but it involves the handling of call state transitions.

Exploitation

An attacker with network access can exploit this by initiating a FaceTime call and manipulating the call termination process. No authentication is required beyond being able to place a call. The attacker can cause the call to appear ended while audio transmission continues, allowing the attacker to capture audio data from the other participant.

Impact

Successful exploitation results in information disclosure of audio data from a call that the victim believed had ended. The attacker gains access to potentially sensitive conversations without the victim's knowledge. The impact is limited to audio data; no code execution or privilege escalation is indicated.

Mitigation

Apple addressed this issue in iOS 10.1 [2] and macOS 10.12.1 [1], released on October 24, 2016. Users should update their devices to these versions or later. No workarounds are available.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.