Release record

iOS 9.3.5

Full article
Public release
Recorded milestones
1
Beta cycle
Average interval
Public release
Aug 25, 2016

Release notes

Overview

Editorial synthesis with inline references and a source ledger when citations are available.

iOS 9.3.5 was an explicitly security-focused maintenance release rather than a feature update.[1]

Apple’s bulletin enumerates exactly three corrections: a kernel information disclosure, a kernel memory-corruption path to privileged code execution, and a WebKit memory-corruption path triggered by malicious web content.[2][3]

Source ledger

References

Sources are linked to the claims they support. Publication and access dates are shown when available.

  1. About iOS 9 Updates

    Apple Support · 2026-07-30 · iOS 9.3.5

    Back to text ↑
  2. Apple security updates (2016 to 2017)

    Apple Support · Apple · 2023-11-06T00:00:00.000Z · iOS 9.3.5 — August 25, 2016

    Back to text ↑
  3. About the Security Content of iOS 9.3.5

    Apple Support · 2026-07-30 · Kernel and WebKit — CVE-2016-4655, CVE-2016-4656, and CVE-2016-4657

    Back to text ↑
  4. About the Security Content of iOS 9.3.5

    Apple Support · 2026-07-30 · iOS 9.3.5 security content

Documented & observed

Changes in this version

Source-linked features, fixes, known issues, removals, and community-observed behavior recorded across this version’s appearances and verified builds.

Release changes

Changed in this release

Features, fixes, removals, and regressions first observed in this release record.

security · fixed

Kernel information-disclosure fix

documentedconfirmed

Apple addressed CVE-2016-4655, a kernel validation issue that could expose kernel memory to an application.

Recorded at Public

  1. [1] About the Security Content of iOS 9.3.5 · Kernel — CVE-2016-4655

security · fixed

WebKit memory-corruption fix

documentedconfirmed

Apple addressed CVE-2016-4657, a WebKit memory-corruption vulnerability triggered by maliciously crafted web content.

Recorded at Public

  1. [1] About the Security Content of iOS 9.3.5 · WebKit — CVE-2016-4657

security · fixed

Kernel memory-corruption fix

documentedconfirmed

Apple addressed CVE-2016-4656, a kernel memory-corruption vulnerability with the documented potential for privileged code execution.

Recorded at Public

  1. [1] About the Security Content of iOS 9.3.5 · Kernel — CVE-2016-4656

Milestones

Release history

Every recorded channel appearance in chronological order. Open an appearance for any available build, scope, notes, and sources.

  1. Public release

    Public

    Source-linked recordEditorially verified

    The public iOS 9.3.5 release delivered three documented security corrections affecting kernel information disclosure, kernel code execution, and WebKit code execution.

    Availability
    available
    Sources
    5 linked
    Open this appearance

Historical context

Cycle comparison

Pace, intervals, and duration compared with earlier releases on the same platform.

Official release notes