CVE-2016-4655 is a kernel information-disclosure vulnerability in Apple iOS versions before 9.3.5. A crafted application can obtain sensitive information from kernel memory. The vulnerability was used as the kernel memory disclosure component of the Trident exploit chain, where it enabled bypass of Kernel Address Space Layout Randomization (KASLR) by identifying the iOS kernel base address.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/apple_ios/browser/webkit_trident.rb) that exploits a use-after-free (UAF) vulnerability in WebKit's JavaScriptCore library, as used in Apple iOS. The exploit targets CVE-2016-4655, CVE-2016-4656, and CVE-2016-4657, which were part of the 'Trident' exploit chain used by the Pegasus spyware. The module sets up an HTTP server that serves a malicious web page containing JavaScript to trigger the vulnerability in the target's browser. Depending on the requested URI, the server delivers different binaries (loader32, loader64, exploit64, payload32) to facilitate exploitation and payload delivery. The default payload is a Meterpreter reverse TCP shell for iOS (aarch64), providing the attacker with remote access to the device. The module is weaponized, allowing for customizable payloads and is suitable for operational use. The main attack vector is via a browser on a vulnerable iOS device visiting the attacker's server. The code is written in Ruby (Metasploit module) and includes embedded JavaScript for the browser exploit.
This repository implements a jailbreak exploit for iOS 8.4.1, leveraging CVE-2016-4655 (an information leak in the AppleKeyStore IOKit service) and CVE-2016-4656 (a kernel memory corruption vulnerability). The code is structured as an Xcode project targeting iOS devices, with the main exploit logic in 'skybreak/kleak.c' and 'skybreak/exploit.h'. The exploit works by crafting a malicious serialized dictionary and sending it to the AppleKeyStore service via IOKit interfaces, causing the kernel to leak the kernel slide (kslide) value. This value is essential for bypassing KASLR and is a prerequisite for further kernel exploitation (such as privilege escalation or code execution). The repository includes Objective-C code for the app interface, but the core exploit is written in C. The exploit is operational and can be used as part of a jailbreak chain for iOS 8.4.1. No network endpoints are present; the attack vector is local, requiring code execution on the target device.
This repository is a local privilege escalation proof-of-concept (PoC) exploit for OS X 10.11.6, targeting CVE-2016-4655 (kernel infoleak) and CVE-2016-4656 (use-after-free in IOKit). The structure consists of a main exploit file (main.c), a ROP utility library (librop/librop.c and librop/librop.h), a Makefile for building, and a README.md with background information. The exploit works by first leaking the kernel address space layout randomization (KASLR) slide using a crafted serialized dictionary and IOKit interfaces, then exploiting a use-after-free vulnerability to execute a ROP chain in kernel context. The ROP chain manipulates kernel structures to escalate privileges and finally spawns a root shell (/bin/bash). The exploit is written in C, requires local access, and is specific to the vulnerable OS X version and kernel. Notable fingerprintable endpoints include the kernel image path, the use of /bin/bash, and the targeting of the IOHDIXController IOKit service.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.