CVE-2016-4622 is a WebKit memory corruption vulnerability affecting Apple iOS before 9.3.3, Safari before 9.1.2, tvOS before 9.2.2, and supported OS X releases receiving the July 2016 WebKit security update. The flaw is described as one of multiple memory corruption issues in WebKit that could be triggered when a target processes maliciously crafted web content. Apple indicated the issue was addressed through improved memory handling. Successful exploitation could occur by enticing a user to visit a malicious website or otherwise process attacker-controlled web content, leading to arbitrary code execution or, in some cases, denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive analysis and proof-of-concept exploit for CVE-2016-4622, a memory disclosure vulnerability in WebKit's JavaScriptCore engine. The exploit leverages a TOCTOU bug in the Array.slice() fast path, where a crafted valueOf() method can shrink the array during parameter conversion, causing out-of-bounds memory to be copied and leaked. The main exploit script (Exploit/poc-memleak.js) demonstrates this primitive, and an educational script (Exploit/slice_over_array.js) explains the mechanics of Array.slice(). The repository also includes pre-built JavaScriptCore binaries (both debug and ASAN-enabled) for macOS, allowing for direct testing and analysis. The Readme.md provides an in-depth technical breakdown, exploitation walkthrough, and references. The exploit is a proof-of-concept for information disclosure and does not provide direct code execution, but it forms the basis for further exploitation (e.g., addrof/fakeobj primitives). The attack vector is browser-based, targeting users or systems running the vulnerable JavaScriptCore engine.
This repository is a proof-of-concept (PoC) exploit for CVE-2016-4622, a vulnerability in WebKit's JavaScriptCore (JSC) engine that allows attackers to achieve arbitrary memory read and write in the browser process. The repository contains several JavaScript modules (utils.js, int64.js, pwn.js) that provide utility functions, 64-bit integer manipulation, and the main exploit logic, respectively. Two HTML files (email.html and pwn.html) serve as entry points for different exploit demonstrations: - 'email.html' demonstrates how the exploit can be used to disable the browser's same-origin policy and exfiltrate a user's Gmail inbox if the user is authenticated, by making a cross-origin XMLHttpRequest to 'https://mail.google.com/mail/u/0/#inbox'. - 'pwn.html' demonstrates how the exploit can be used to inject and execute arbitrary shellcode in JIT-compiled memory, effectively achieving code execution in the browser process. The exploit works by abusing the vulnerability to create fake JavaScript objects and manipulate their internal structures, ultimately providing a 'memory' object for arbitrary memory access. The code is version-dependent and targets specific versions of WebKit JSC. The repository is structured for research and demonstration purposes, not for weaponized exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A WebKit memory corruption vulnerability that may allow arbitrary code execution when visiting a maliciously crafted website.
A WebKit memory corruption vulnerability that may allow arbitrary code execution via malicious web content.
A WebKit memory corruption vulnerability that could allow arbitrary code execution via a malicious website.
A JavaScriptCore vulnerability referenced only as background material for same-origin policy discussion.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.