security · fixed
Kernel information-disclosure fix
Apple addressed CVE-2016-4655, a kernel validation issue that could expose kernel memory to an application.
Recorded at Public
- [1] About the Security Content of iOS 9.3.5 · Kernel — CVE-2016-4655
Release record
Release notes
Editorial synthesis with inline references and a source ledger when citations are available.
iOS 9.3.5 was an explicitly security-focused maintenance release rather than a feature update.[1]
Source ledger
Sources are linked to the claims they support. Publication and access dates are shown when available.
Apple Support · Apple · 2023-11-06T00:00:00.000Z · iOS 9.3.5 — August 25, 2016
Apple Support · 2026-07-30 · Kernel and WebKit — CVE-2016-4655, CVE-2016-4656, and CVE-2016-4657
Apple Support · 2026-07-30 · iOS 9.3.5 security content
Documented & observed
Source-linked features, fixes, known issues, removals, and community-observed behavior recorded across this version’s appearances and verified builds.
Release changes
Features, fixes, removals, and regressions first observed in this release record.
security · fixed
Apple addressed CVE-2016-4655, a kernel validation issue that could expose kernel memory to an application.
Recorded at Public
security · fixed
Apple addressed CVE-2016-4657, a WebKit memory-corruption vulnerability triggered by maliciously crafted web content.
Recorded at Public
security · fixed
Apple addressed CVE-2016-4656, a kernel memory-corruption vulnerability with the documented potential for privileged code execution.
Recorded at Public
Milestones
Every recorded channel appearance in chronological order. Open an appearance for any available build, scope, notes, and sources.
Public release
The public iOS 9.3.5 release delivered three documented security corrections affecting kernel information disclosure, kernel code execution, and WebKit code execution.
Historical context
Pace, intervals, and duration compared with earlier releases on the same platform.