Apple Releases Update for iOS 12 to Patch Exploited Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-32893 | Out-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known. Do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted. | 8.8 | 10% | KEV |
| masshundreds of millions of devices (Apple's active iPhone/Mac installed base plus Safari/WebKit users) |
Full article295 words · extracted from infosecurity-magazine.com · click to collapse
Apple has released an iOS 12 update for older iPhone and iPad devices, patching a vulnerability that was reportedly exploited by threat actors.
According to a document published by the company on Wednesday, August 31, the flaw would allow the processing of maliciously crafted web content, which in turn led to arbitrary code execution.
"Apple is aware of a report that this issue may have been actively exploited," the tech company wrote.
The 275 MB update released to patch the vulnerability is available for several older Apple devices, including the iPhone 5S, iPhone 6, iPhone 6 Plus, iPad Air, iPad Mini 2, iPad Mini 3 and iPod Touch (6th gen).
The software version has been updated to 12.5.6, build number 16H71. It seems to fix the security vulnerability (tracked CVE-2022-32893), which the company recently patched in the iOS 15.6.1 update a fortnight ago.
The critical bug, rated 8.8 according to the Common Vulnerability Scoring System (CVSS), was also spotted by the Cybersecurity and Infrastructure Security Agency (CISA), which wrote an advisory about it last month.
From a technical standpoint, Apple said it fixed the flaw by improving bounds checking within the operating system (OS). Just like with the original vulnerability, the company credited an anonymous researcher for reporting the vulnerability.
Users of the aforementioned iOS devices are recommended to apply the updates as soon as possible to mitigate the impact of potential threats.
The patch comes weeks after Apple announced a new set of privacy and security-focussed iPhone features grouped under a 'Lockdown Mode.'
Also in mobile-focused news, Google patched a critical Android Bluetooth flaw in August. More recently, Apple announced a new program designed to reward researchers who find bugs in its open source projects from $100 to $31,337 per bounty.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apple-updates-ios-12/