CVE-2016-4741: Apple iPhone OS

Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.

The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.

Affected products

  • Apple iPhone OS: up to and including 9.3.5

Published 2016-09-18. Last modified 2026-06-17.