WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon