CVE-2022-32917
KEVmassOut-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Kernel-Privilege Code Execution
CISA: Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
CVE-2022-32917 is an out-of-bounds write (CWE-787) in the Apple operating system kernel that the vendor fixed with improved bounds checks. A local application running on a vulnerable device can trigger the flaw to execute arbitrary code with kernel privileges, giving an attacker full control of the device; the local (AV:L) attack vector means the attacker must already be able to run code on the device, such as through a malicious app, rather than reaching the flaw over the network. Users of Apple devices running iOS, iPadOS, or macOS versions earlier than the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-14 with no public proof-of-concept known.
What to do: Update affected devices without delay to iOS 16 or iOS 15.7, iPadOS 15.7, macOS Monterey 12.6, or macOS Big Sur 11.7 (or any later release). Inventory Apple endpoints for outdated OS versions and prioritize patching because the flaw is on CISA's KEV catalog and was reported actively exploited. Since exploitation requires already running code on the device, review installed apps and treat the flaw as exploitable when chained with other local or app-delivery attack vectors.
| Apple iPhone OS (iOS) | Versions prior to iOS 15.7 and prior to iOS 16 (fixed in iOS 15.7 and iOS 16) |
| Apple iPadOS | Versions prior to iPadOS 15.7 (fixed in iPadOS 15.7) |
| Apple macOS Monterey | Versions prior to 12.6 (fixed in macOS Monterey 12.6) |
| Apple macOS Big Sur | Versions prior to 11.7 (fixed in macOS Big Sur 11.7) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple iOS, iPadOS, and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H