ZeroHour

CVE-2022-42827

KEVmass

Actively Exploited Out-of-Bounds Write in Apple iOS and iPadOS Kernel

CISA: Apple iOS and iPadOS Out-of-Bounds Write Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p62
Published
()
KEV added
AI analysis

CVE-2022-42827 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS and iPadOS, caused by insufficient bounds checking and fixed with improved bounds checking. It is triggered locally by a malicious application running on a vulnerable device, consistent with the CVSS vector (local attack vector, user interaction required, no special privileges). A successful attacker can execute arbitrary code with kernel privileges, escaping the app sandbox and gaining full control of the device's operating system layer. Any iPhone or iPad running iOS/iPadOS versions below the fixed releases (iOS 15.7.1, iPadOS 15.7.1, iOS 16.1, iPadOS 16) is affected, which at the time of disclosure covered essentially the entire unpatched iOS/iPadOS fleet. Apple reported the flaw may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-25; no public proof-of-concept is known, but in-the-wild exploitation is confirmed.

What to do: Update all iPhones and iPads to iOS 15.7.1 / iPadOS 15.7.1 at minimum, or preferably iOS 16.1 / iPadOS 16 or later. Because exploitation requires running a malicious app on the device, treat unpatched devices as at-risk, verify fleet OS builds via MDM or device inventory, and restrict app installs from untrusted sources until patched. The CVE is on CISA's KEV list, making patching mandatory for federal agencies and strongly recommended for all organizations.

Affected
Apple iPhone OS (iOS)All iOS versions prior to 15.7.1 and prior to 16.1
Apple iPadOSAll iPadOS versions prior to 15.7.1 and prior to 16
Estimated exposure
masshundreds of millions of devices (effectively all iPhones/iPads not yet on iOS 15.7.1/iPadOS 15.7.1 or iOS 16.1/iPadOS 16 at disclosure) — Apple's combined iPhone/iPad active install base exceeds one billion devices, and every device below the fixed builds at the time of disclosure was vulnerable, so even the unpatched fraction of the fleet puts exposure in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS and iPadOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news