CVE-2016-1751: Apple iPhone OS

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

The kernel in Apple iOS before 9.3, tvOS before 9.2, and watchOS before 2.2 does not properly restrict the execute permission, which allows attackers to bypass a code-signing protection mechanism via a crafted app.

Affected products

  • Apple iPhone OS: before 9.3 (fixed in 9.3)
  • Apple tvOS: before 9.2 (fixed in 9.2)
  • Apple watchOS: before 2.2 (fixed in 2.2)

Published 2016-03-24. Last modified 2026-06-17.