Apple fixes exploited iOS, iPadOS zero-day (CVE-2022-42827)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-32946 | This issue was addressed with improved entitlements. This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2022-42827 | Actively Exploited Out-of-Bounds Write in Apple iOS and iPadOS Kernel CVE-2022-42827 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS and iPadOS, caused by insufficient bounds checking and fixed with improved bounds checking. It is triggered locally by a malicious application running on a vulnerable device, consistent with the CVSS vector (local attack vector, user interaction required, no special privileges). A successful attacker can execute arbitrary code with kernel privileges, escaping the app sandbox and gaining full control of the device's operating system layer. Any iPhone or iPad running iOS/iPadOS versions below the fixed releases (iOS 15.7.1, iPadOS 15.7.1, iOS 16.1, iPadOS 16) is affected, which at the time of disclosure covered essentially the entire unpatched iOS/iPadOS fleet. Apple reported the flaw may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-25; no public proof-of-concept is known, but in-the-wild exploitation is confirmed. Do: Update all iPhones and iPads to iOS 15.7.1 / iPadOS 15.7.1 at minimum, or preferably iOS 16.1 / iPadOS 16 or later. Because exploitation requires running a malicious app on the device, treat unpatched devices as at-risk, verify fleet OS builds via MDM or device inventory, and restrict app installs from untrusted sources until patched. The CVE is on CISA's KEV list, making patching mandatory for federal agencies and strongly recommended for all organizations. | 7.8 | 1% | KEV |
| masshundreds of millions of devices (effectively all iPhones/iPads not yet on iOS 15.7.1/iPadOS 15.7.1 or iOS 16.1/iPadOS 16 at disclosure) |
Full article262 words · extracted from helpnetsecurity.com · click to collapse
For the ninth time this year, Apple has released fixes for a zero-day vulnerability (CVE-2022-42827) exploited by attackers to compromise iPhones.

About CVE-2022-42827
CVE-2022-42827 is an out-of-bounds write issue in the iOS and iPadOS kernel, which can be exploited to allow a malicious application to execute arbitrary code with kernel privileges.
“Apple is aware of a report that this issue may have been actively exploited,” the company said, though – as per usual – did not offer details about the attack(s).
Reported by an anonymous researcher, the vulnerability has been fixed with improved bounds checking in iOS 16.1 and iPadOS 16, which is available for:
- iPhone 8 and later
- iPad Pro (all models)
- iPad Air 3rd generation and later
- iPad 5th generation and later
- iPad mini 5th generation and later
iOS 16.1 and iPadOS 16 also come with fixes for 19 additional CVE-numbered security issues, including a flaw (CVE-2022-32946) in the Bluetooth component that could allow an app to record audio using a pair of connected AirPods, and many other code execution holes.
Other security updates
Mac users, whether they are running macOS Big Sur, Monterey, or Ventura (the latest version of the OS, with new security and privacy features), have also security updates available.
Ventura’s is particularly sizeable, with fixes for 113 issues (40 of which are in the Vim text editor).
Safari, tvOS and watchOS security updates have also been released.
UPDATE (October 28, 2022, 05:25 a.m. ET):
Apple has released updates for the iOS 15 and iPadOS 15 branch, which include the patch for CVE-2022-42827.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/10/25/cve-2022-42827/