Apple Fixes Actively Exploited iOS and iPadOS Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-32894 | Kernel Out-of-Bounds Write in Apple iOS, iPadOS and macOS — Actively Exploited Apple's August 2022 emergency update fixed an out-of-bounds write (CWE-787) in the kernel of iOS, iPadOS and macOS Monterey, corrected in iOS/iPadOS 15.6.1 and macOS Monterey 12.5.1. The attack vector is local (CVSS AV:L with user interaction required), meaning a victim must run a malicious application or file that triggers the flawed bounds checking and overwrites kernel memory. Successful exploitation allows arbitrary code execution with kernel privileges, effectively giving the attacker full control of the device. Users of iPhones, iPads and Macs running versions before the patched releases are affected; watchOS also appears in the product data, though no fixed version for it is specified. Apple acknowledged reports of active exploitation and CISA added the flaw to its KEV catalog on 2022-08-18, so in-the-wild exploitation is confirmed even though no public PoC is known. Do: Update iPhones and iPads to iOS/iPadOS 15.6.1 and Macs to macOS Monterey 12.5.1, per Apple's advisories and the KEV required action to apply vendor updates. For older devices that cannot run iOS 15, check Apple's security advisories for a vendor-supplied update applicable to that hardware generation. Inventory fleet OS versions (e.g., via MDM) and treat unpatched devices as at risk of kernel-level compromise. | 7.8 | 3% | KEV |
| masson the order of 1 billion+ active devices (Apple's iPhone, iPad and Mac installed base) | |
| CVE-2022-32917 | Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Kernel-Privilege Code Execution CVE-2022-32917 is an out-of-bounds write (CWE-787) in the Apple operating system kernel that the vendor fixed with improved bounds checks. A local application running on a vulnerable device can trigger the flaw to execute arbitrary code with kernel privileges, giving an attacker full control of the device; the local (AV:L) attack vector means the attacker must already be able to run code on the device, such as through a malicious app, rather than reaching the flaw over the network. Users of Apple devices running iOS, iPadOS, or macOS versions earlier than the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-09-14 with no public proof-of-concept known. Do: Update affected devices without delay to iOS 16 or iOS 15.7, iPadOS 15.7, macOS Monterey 12.6, or macOS Big Sur 11.7 (or any later release). Inventory Apple endpoints for outdated OS versions and prioritize patching because the flaw is on CISA's KEV catalog and was reported actively exploited. Since exploitation requires already running code on the device, review installed apps and treat the flaw as exploitable when chained with other local or app-delivery attack vectors. | 7.8 | 6% | KEV |
| masshundreds of millions to over a billion devices (Apple's active installed base of iPhones, iPads, and Macs; all devices on OS versions older than the listed… | |
| CVE-2022-42823 +1 in the same advisory: …32922 | A type confusion issue was addressed with improved memory handling. A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2022-42808 +1 in the same advisory: …42813 | An out-of-bounds write issue was addressed with improved bounds checking. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2022-42827 | Actively Exploited Out-of-Bounds Write in Apple iOS and iPadOS Kernel CVE-2022-42827 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS and iPadOS, caused by insufficient bounds checking and fixed with improved bounds checking. It is triggered locally by a malicious application running on a vulnerable device, consistent with the CVSS vector (local attack vector, user interaction required, no special privileges). A successful attacker can execute arbitrary code with kernel privileges, escaping the app sandbox and gaining full control of the device's operating system layer. Any iPhone or iPad running iOS/iPadOS versions below the fixed releases (iOS 15.7.1, iPadOS 15.7.1, iOS 16.1, iPadOS 16) is affected, which at the time of disclosure covered essentially the entire unpatched iOS/iPadOS fleet. Apple reported the flaw may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-25; no public proof-of-concept is known, but in-the-wild exploitation is confirmed. Do: Update all iPhones and iPads to iOS 15.7.1 / iPadOS 15.7.1 at minimum, or preferably iOS 16.1 / iPadOS 16 or later. Because exploitation requires running a malicious app on the device, treat unpatched devices as at-risk, verify fleet OS builds via MDM or device inventory, and restrict app installs from untrusted sources until patched. The CVE is on CISA's KEV list, making patching mandatory for federal agencies and strongly recommended for all organizations. | 7.8 | 1% | KEV |
| masshundreds of millions of devices (effectively all iPhones/iPads not yet on iOS 15.7.1/iPadOS 15.7.1 or iOS 16.1/iPadOS 16 at disclosure) |
Full article311 words · extracted from infosecurity-magazine.com · click to collapse
Apple released new updates on Monday to patch a zero-day vulnerability in iOS and iPadOS devices that has reportedly been actively exploited in the wild.
The out-of-bounds write issue in the kernel (tracked CVE-2022-42827) could be exploited by rogue applications to execute arbitrary code with admin privileges.
"Apple is aware of a report that this issue may have been actively exploited," the company wrote. "An out-of-bounds write issue was addressed with improved bounds checking."
The update is available for iPhone 8 and later, iPad Pro (all models), iPad 5th generation and later, iPad Air 3rd generation and later and iPad mini 5th generation and later. An anonymous researcher has been credited for discovering the vulnerability.
The fixed vulnerability is the third of this kind Apple fixed over the last couple of months after CVE-2022-32894 and CVE-2022-32917, both of which were also reportedly exploited in the wild.
Beyond CVE-2022-42827, the latest update from Apple also patches up 19 other security vulnerabilities. Of these, CVE-2022-42813, CVE-2022-42808, CVE-2022-42823 and CVE-2022-32922 could all lead to arbitrary code execution.
A complete list of the vulnerabilities fixed this week in iOS 16.1, including those affecting AppleMobileFileIntegrity, AVEVideoEncoder, Core Bluetooth, GPU Drivers, IOHIDFamily, Sandbox and Shortcuts, is available on the company's changelog page for the iOS 16.1 update.
More generally, there have been at least eight documented in-the-wild zero-day attacks against Apple devices this year across macOS, iOS and iPadOS devices.
In all of these cases, Apple did not disclose details on the active exploitation or provide indicators of compromise (IoC) or other data to aid iOS users in looking for signs of infections.
The iOS 16.1 update comes weeks after Fast Company's Apple News account was breached and sent obscene push notifications to users on their mobile devices. The account was then removed by Apple News and has not been added back at the time of writing.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apple-fixes-exploited-ios-and/