ZeroHour

CVE-2022-32917

KEVmass

Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Kernel-Privilege Code Execution

CISA: Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
6%p92
Published
()
KEV added
AI analysis

CVE-2022-32917 is an out-of-bounds write (CWE-787) in the Apple operating system kernel that the vendor fixed with improved bounds checks. A local application running on a vulnerable device can trigger the flaw to execute arbitrary code with kernel privileges, giving an attacker full control of the device; the local (AV:L) attack vector means the attacker must already be able to run code on the device, such as through a malicious app, rather than reaching the flaw over the network. Users of Apple devices running iOS, iPadOS, or macOS versions earlier than the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-14 with no public proof-of-concept known.

What to do: Update affected devices without delay to iOS 16 or iOS 15.7, iPadOS 15.7, macOS Monterey 12.6, or macOS Big Sur 11.7 (or any later release). Inventory Apple endpoints for outdated OS versions and prioritize patching because the flaw is on CISA's KEV catalog and was reported actively exploited. Since exploitation requires already running code on the device, review installed apps and treat the flaw as exploitable when chained with other local or app-delivery attack vectors.

Affected
Apple iPhone OS (iOS)Versions prior to iOS 15.7 and prior to iOS 16 (fixed in iOS 15.7 and iOS 16)
Apple iPadOSVersions prior to iPadOS 15.7 (fixed in iPadOS 15.7)
Apple macOS MontereyVersions prior to 12.6 (fixed in macOS Monterey 12.6)
Apple macOS Big SurVersions prior to 11.7 (fixed in macOS Big Sur 11.7)
Estimated exposure
masshundreds of millions to over a billion devices (Apple's active installed base of iPhones, iPads, and Macs; all devices on OS versions older than the listed… — Public installed-base figures put Apple's active iOS/iPadOS devices at more than a billion and Macs at well over 100 million, and every device running an OS version earlier than the fixed releases is potentially affected, making this a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news