CVE-2016-4769: Apple iTunes

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

Affected products

  • Apple iTunes: up to and including 12.4.3
  • Apple Safari: up to and including 9.1.3

Published 2016-09-25. Last modified 2026-06-17.