CVE-2016-4654: Apple iPhone OS

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

Affected products

  • Apple iPhone OS: version 9.3.3 only

Published 2016-08-18. Last modified 2026-06-17.