ZeroHour
Security Affairspublished ()ingested @securityaffairs

Apple fixed the ninth actively exploited zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22587
Memory Corruption in Apple iOS, iPadOS, and macOS Allows Kernel-Privilege Code Execution

CVE-2022-22587 is a memory corruption flaw (CWE-787, out-of-bounds write) in Apple's operating systems that Apple addressed with improved input validation. It is triggered by a malicious application already running on a vulnerable device, which can exploit the corruption to execute arbitrary code with kernel privileges — the highest privilege level of the OS. All iPhones and iPads running iOS/iPadOS versions earlier than 15.3 and Macs running macOS Monterey earlier than 12.2 or Big Sur earlier than 11.6.3 are affected. Apple reported the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28; EPSS rates it at 11.6% probability of exploitation in the next 30 days (96th percentile). It was one of two actively exploited Apple zero-days patched in Apple's January 2022 emergency updates.

Do: Update iPhones and iPads to iOS/iPadOS 15.3 and Macs to macOS Monterey 12.2 or Big Sur 11.6.3 (or later). Inventory managed fleets for devices below these versions, since the flaw is exploited in the wild and CISA KEV requires applying vendor updates. Until devices are patched, limit exposure by avoiding installation of untrusted applications on vulnerable iPhones, iPads, and Macs.

9.812% KEV
  • Apple iPhone OS (iOS) iOS versions earlier than 15.3 (fixed in iOS 15.3)
  • Apple iPadOS iPadOS versions earlier than 15.3 (fixed in iPadOS 15.3)
  • Apple macOS Monterey macOS Monterey versions earlier than 12.2 (fixed in 12.2)
  • +1 more
mass>1 billion active Apple devices (all iPhones, iPads, and Macs below the fixed versions)
CVE-2022-22594
A cross-origin issue in the IndexDB API was addressed with improved input validation.

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

NVD description · AI analysis pending
6.5<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2022-22620
WebKit Use-After-Free (CVE-2022-22620) Enables RCE on iOS, iPadOS, and macOS

CVE-2022-22620 is a use-after-free (CWE-416) in Apple's WebKit browser engine, the component that renders web content on iPhones, iPads, Macs, and Safari. An attacker triggers it by getting a victim to process maliciously crafted web content, such as visiting an attacker-controlled webpage, requiring no privileges and only user interaction with the content. Successful exploitation may lead to arbitrary code execution in the context of the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High). All devices running iOS or iPadOS before 15.3.1, macOS Monterey before 12.2.1, or Safari before 15.3 are affected, which effectively means the broad Apple user base at the time of disclosure. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-11 and carries a 16.2% EPSS probability of exploitation in the next 30 days (97th percentile).

Do: Update iPhones and iPads to iOS/iPadOS 15.3.1, Macs to macOS Monterey 12.2.1, and Safari to version 15.3 (builds 16612.4.9.1.8 or 15612.4.9.1.8), per Apple's vendor instructions. Inventory for devices still on pre-patch versions, prioritizing user workstations and mobile devices that browse web or HTML email content, since WebKit loads content automatically. Note the vulnerability is listed in CISA's KEV catalog with 'apply updates per vendor instructions' as the required action, so patching is the only reliable mitigation.

8.816% KEV
  • Apple iOS (iPhone OS) prior to iOS 15.3.1
  • Apple iPadOS prior to iPadOS 15.3.1
  • Apple macOS (Monterey) prior to macOS Monterey 12.2.1
  • +1 more
mass≈1 billion+ Apple devices (WebKit is the system web engine on every iPhone, iPad, and Mac)
CVE-2022-22675
+1 in the same advisory: …22674
Out-of-Bounds Write in Apple macOS/iOS Kernel Allows Arbitrary Code Execution

CVE-2022-22675 is an out-of-bounds write vulnerability (CWE-787) in the Apple kernel, addressed through improved bounds checking. It is triggered locally — the CVSS vector shows a local attack vector with user interaction, meaning an application running on the device can trigger the memory corruption. Successful exploitation allows an application to execute arbitrary code with kernel privileges, giving the attacker full control over the affected device. Users of iPhone, iPad, Mac, Apple TV, and Apple Watch running versions prior to the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-04.

Do: Update to iOS/iPadOS 15.4.1, macOS Monterey 12.3.1 or macOS Big Sur 11.6.6, tvOS 15.5, and watchOS 8.6 as required by CISA. Because the flaw is exploited in the wild and requires only a malicious local application, prioritize patching user-facing iPhone, iPad, and Mac fleets first. There is no public PoC; verify installed OS versions on managed devices and confirm remediation after the updates are applied.

7.8
group max
12% KEV
  • apple iphone_os (iOS) prior to 15.4.1
  • apple ipados prior to 15.4.1
  • apple macos (Big Sur) prior to 11.6.6
  • +3 more
mass≈1 billion+ active Apple devices across iPhone, iPad, Mac, Apple TV, and Apple Watch
CVE-2022-32894
Kernel Out-of-Bounds Write in Apple iOS, iPadOS and macOS — Actively Exploited

Apple's August 2022 emergency update fixed an out-of-bounds write (CWE-787) in the kernel of iOS, iPadOS and macOS Monterey, corrected in iOS/iPadOS 15.6.1 and macOS Monterey 12.5.1. The attack vector is local (CVSS AV:L with user interaction required), meaning a victim must run a malicious application or file that triggers the flawed bounds checking and overwrites kernel memory. Successful exploitation allows arbitrary code execution with kernel privileges, effectively giving the attacker full control of the device. Users of iPhones, iPads and Macs running versions before the patched releases are affected; watchOS also appears in the product data, though no fixed version for it is specified. Apple acknowledged reports of active exploitation and CISA added the flaw to its KEV catalog on 2022-08-18, so in-the-wild exploitation is confirmed even though no public PoC is known.

Do: Update iPhones and iPads to iOS/iPadOS 15.6.1 and Macs to macOS Monterey 12.5.1, per Apple's advisories and the KEV required action to apply vendor updates. For older devices that cannot run iOS 15, check Apple's security advisories for a vendor-supplied update applicable to that hardware generation. Inventory fleet OS versions (e.g., via MDM) and treat unpatched devices as at risk of kernel-level compromise.

7.83% KEV
  • Apple iPhone OS (iOS) all versions prior to iOS 15.6.1
  • Apple iPadOS all versions prior to iPadOS 15.6.1
  • Apple macOS Monterey all versions prior to macOS Monterey 12.5.1
  • +1 more
masson the order of 1 billion+ active devices (Apple's iPhone, iPad and Mac installed base)
CVE-2022-32917
Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Kernel-Privilege Code Execution

CVE-2022-32917 is an out-of-bounds write (CWE-787) in the Apple operating system kernel that the vendor fixed with improved bounds checks. A local application running on a vulnerable device can trigger the flaw to execute arbitrary code with kernel privileges, giving an attacker full control of the device; the local (AV:L) attack vector means the attacker must already be able to run code on the device, such as through a malicious app, rather than reaching the flaw over the network. Users of Apple devices running iOS, iPadOS, or macOS versions earlier than the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-14 with no public proof-of-concept known.

Do: Update affected devices without delay to iOS 16 or iOS 15.7, iPadOS 15.7, macOS Monterey 12.6, or macOS Big Sur 11.7 (or any later release). Inventory Apple endpoints for outdated OS versions and prioritize patching because the flaw is on CISA's KEV catalog and was reported actively exploited. Since exploitation requires already running code on the device, review installed apps and treat the flaw as exploitable when chained with other local or app-delivery attack vectors.

7.86% KEV
  • Apple iPhone OS (iOS) Versions prior to iOS 15.7 and prior to iOS 16 (fixed in iOS 15.7 and iOS 16)
  • Apple iPadOS Versions prior to iPadOS 15.7 (fixed in iPadOS 15.7)
  • Apple macOS Monterey Versions prior to 12.6 (fixed in macOS Monterey 12.6)
  • +1 more
masshundreds of millions to over a billion devices (Apple's active installed base of iPhones, iPads, and Macs; all devices on OS versions older than the listed…
CVE-2022-42827
Actively Exploited Out-of-Bounds Write in Apple iOS and iPadOS Kernel

CVE-2022-42827 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS and iPadOS, caused by insufficient bounds checking and fixed with improved bounds checking. It is triggered locally by a malicious application running on a vulnerable device, consistent with the CVSS vector (local attack vector, user interaction required, no special privileges). A successful attacker can execute arbitrary code with kernel privileges, escaping the app sandbox and gaining full control of the device's operating system layer. Any iPhone or iPad running iOS/iPadOS versions below the fixed releases (iOS 15.7.1, iPadOS 15.7.1, iOS 16.1, iPadOS 16) is affected, which at the time of disclosure covered essentially the entire unpatched iOS/iPadOS fleet. Apple reported the flaw may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-25; no public proof-of-concept is known, but in-the-wild exploitation is confirmed.

Do: Update all iPhones and iPads to iOS 15.7.1 / iPadOS 15.7.1 at minimum, or preferably iOS 16.1 / iPadOS 16 or later. Because exploitation requires running a malicious app on the device, treat unpatched devices as at-risk, verify fleet OS builds via MDM or device inventory, and restrict app installs from untrusted sources until patched. The CVE is on CISA's KEV list, making patching mandatory for federal agencies and strongly recommended for all organizations.

7.81% KEV
  • Apple iPhone OS (iOS) All iOS versions prior to 15.7.1 and prior to 16.1
  • Apple iPadOS All iPadOS versions prior to 15.7.1 and prior to 16
masshundreds of millions of devices (effectively all iPhones/iPads not yet on iOS 15.7.1/iPadOS 15.7.1 or iOS 16.1/iPadOS 16 at disclosure)
Full article217 words · extracted from securityaffairs.com · click to collapse

Apple released security updates that addressed the ninth zero-day vulnerability actively exploited in the wild since the start of the year. 

Apple has addressed the ninth zero-day vulnerability exploited in attacks in the wild since the start of the year. The vulnerability, tracked as CVE-2022-42827, is an out-of-bounds write issue that can be exploited by an attacker to execute arbitrary code with kernel privileges.

The flaw was reported to Apple by an anonymous researcher, the company addressed it with improved bounds checking in iOS 16.1 and iPadOS 16.

“Apple is aware of a report that this issue may have been actively exploited.” reads the advisory published by Apple.

The vulnerability impacts iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, iPad mini 5th generation and later.

Apple users are recommended to immediately update their devices to mitigate exposure to attack attempts.

Apple has addressed other eight zero-day vulnerabilities since January, below is the list of fixed issues:

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Apple zero-day)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/137579/security/apple-fixes-ninth-zero-day.html