CVE-2016-1720: Apple iPhone OS

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

Affected products

  • Apple iPhone OS: before 9.2.1 (fixed in 9.2.1)
  • Apple Mac OS X: before 10.11.3 (fixed in 10.11.3)
  • Apple tvOS: before 9.1.1 (fixed in 9.1.1)
  • Apple watchOS: before 2.2 (fixed in 2.2)

Published 2016-02-01. Last modified 2026-06-17.