Apple fixes actively exploited zero-day in macOS, iOS (CVE-2022-32917)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-32894 | Kernel Out-of-Bounds Write in Apple iOS, iPadOS and macOS — Actively Exploited Apple's August 2022 emergency update fixed an out-of-bounds write (CWE-787) in the kernel of iOS, iPadOS and macOS Monterey, corrected in iOS/iPadOS 15.6.1 and macOS Monterey 12.5.1. The attack vector is local (CVSS AV:L with user interaction required), meaning a victim must run a malicious application or file that triggers the flawed bounds checking and overwrites kernel memory. Successful exploitation allows arbitrary code execution with kernel privileges, effectively giving the attacker full control of the device. Users of iPhones, iPads and Macs running versions before the patched releases are affected; watchOS also appears in the product data, though no fixed version for it is specified. Apple acknowledged reports of active exploitation and CISA added the flaw to its KEV catalog on 2022-08-18, so in-the-wild exploitation is confirmed even though no public PoC is known. Do: Update iPhones and iPads to iOS/iPadOS 15.6.1 and Macs to macOS Monterey 12.5.1, per Apple's advisories and the KEV required action to apply vendor updates. For older devices that cannot run iOS 15, check Apple's security advisories for a vendor-supplied update applicable to that hardware generation. Inventory fleet OS versions (e.g., via MDM) and treat unpatched devices as at risk of kernel-level compromise. | 7.8 | 3% | KEV |
| masson the order of 1 billion+ active devices (Apple's iPhone, iPad and Mac installed base) | |
| CVE-2022-32917 | Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Kernel-Privilege Code Execution CVE-2022-32917 is an out-of-bounds write (CWE-787) in the Apple operating system kernel that the vendor fixed with improved bounds checks. A local application running on a vulnerable device can trigger the flaw to execute arbitrary code with kernel privileges, giving an attacker full control of the device; the local (AV:L) attack vector means the attacker must already be able to run code on the device, such as through a malicious app, rather than reaching the flaw over the network. Users of Apple devices running iOS, iPadOS, or macOS versions earlier than the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-14 with no public proof-of-concept known. Do: Update affected devices without delay to iOS 16 or iOS 15.7, iPadOS 15.7, macOS Monterey 12.6, or macOS Big Sur 11.7 (or any later release). Inventory Apple endpoints for outdated OS versions and prioritize patching because the flaw is on CISA's KEV catalog and was reported actively exploited. Since exploitation requires already running code on the device, review installed apps and treat the flaw as exploitable when chained with other local or app-delivery attack vectors. | 7.8 | 6% | KEV |
| masshundreds of millions to over a billion devices (Apple's active installed base of iPhones, iPads, and Macs; all devices on OS versions older than the listed… |
Full article243 words · extracted from helpnetsecurity.com · click to collapse
Apple has fixed a slew of vulnerabilities in macOS, iOS, and iPadOS, including a zero-day kernel vulnerability (CVE-2022-32917) exploited by attackers in the wild.

About CVE-2022-32917
CVE-2022-32917, reported by an anonymous researcher, may allow a malicious application to execute arbitrary code with kernel privileges.
“Apple is aware of a report that this issue may have been actively exploited,” the company said, and noted that the vulnerability has been remediated with improved bounds checks.
The vulnerability has been fixed in macOS 12.6 (Monterey), macOS 11.7 (Big Sur), iOS 16, and iOS 15.7 and iPadOS 15.7.
As is Apple’s custom, details about the attack(s) taking advantage of this flaw have not been shared, but it’s likely that they are targeted and limited. Nevertheless, users are advised to update their Apple devices as soon as possible.
The updates also contain fixes for similar and less critical vulnerabilities. The Big Sur update also contains a fix for CVE-2022-32894, fixed in August in iOS 15.6.1 and iPadOS 15.6, and macOS 12.5.1.
Apple has been busy fixing zero-days
This is the eight time this year that Apple fixes a zero-day vulnerability in the operating systems powering their Macs and iPhones.
Apple has also released security updates for tvOS and watchOS, but has not yet shared what specific vulnerabilities have been patched in those.
iOS 16 is the most current major release of the iOS mobile operating system, which comes with several new security and privacy features.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/09/13/cve-2022-32917/