CVE-2016-4710: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.

Affected products

  • Apple Mac OS X: up to and including 10.11.6

Published 2016-09-25. Last modified 2026-06-17.