Apple macOS 10.12.2 Safari SSL handshake MiTM Memory Exhaustion

Risk: Medium
Local: No
Remote: Yes
CWE: CWE-399

Apple did not fully patched I do not tested the latest update --- Security Available for: macOS Sierra 10.12.1 Impact: An attacker in a privileged network position may be able to cause a denial of service Description: A validation issue existed in the handling of OCSP responder URLs. This issue was addressed by verifying OCSP revocation status after CA validation and limiting the number of OCSP requests per certificate. CVE-2016-7636: Maksymilian Arciemowicz ( --- Use the latest Safari and macOS and check PoC:


