CVE-2016-4606: Haxx Curl

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

Affected products

  • Haxx Curl: before 7.49.1 (fixed in 7.49.1)

Published 2020-02-21. Last modified 2026-06-17.