ZeroHour
The Recordpublished ()ingested

Apple releases fixes for two zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22587
Memory Corruption in Apple iOS, iPadOS, and macOS Allows Kernel-Privilege Code Execution

CVE-2022-22587 is a memory corruption flaw (CWE-787, out-of-bounds write) in Apple's operating systems that Apple addressed with improved input validation. It is triggered by a malicious application already running on a vulnerable device, which can exploit the corruption to execute arbitrary code with kernel privileges — the highest privilege level of the OS. All iPhones and iPads running iOS/iPadOS versions earlier than 15.3 and Macs running macOS Monterey earlier than 12.2 or Big Sur earlier than 11.6.3 are affected. Apple reported the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28; EPSS rates it at 11.6% probability of exploitation in the next 30 days (96th percentile). It was one of two actively exploited Apple zero-days patched in Apple's January 2022 emergency updates.

Do: Update iPhones and iPads to iOS/iPadOS 15.3 and Macs to macOS Monterey 12.2 or Big Sur 11.6.3 (or later). Inventory managed fleets for devices below these versions, since the flaw is exploited in the wild and CISA KEV requires applying vendor updates. Until devices are patched, limit exposure by avoiding installation of untrusted applications on vulnerable iPhones, iPads, and Macs.

9.812% KEV
  • Apple iPhone OS (iOS) iOS versions earlier than 15.3 (fixed in iOS 15.3)
  • Apple iPadOS iPadOS versions earlier than 15.3 (fixed in iPadOS 15.3)
  • Apple macOS Monterey macOS Monterey versions earlier than 12.2 (fixed in 12.2)
  • +1 more
mass>1 billion active Apple devices (all iPhones, iPads, and Macs below the fixed versions)
CVE-2022-22594
A cross-origin issue in the IndexDB API was addressed with improved input validation.

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

NVD description · AI analysis pending
6.5<1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2022-22620
WebKit Use-After-Free (CVE-2022-22620) Enables RCE on iOS, iPadOS, and macOS

CVE-2022-22620 is a use-after-free (CWE-416) in Apple's WebKit browser engine, the component that renders web content on iPhones, iPads, Macs, and Safari. An attacker triggers it by getting a victim to process maliciously crafted web content, such as visiting an attacker-controlled webpage, requiring no privileges and only user interaction with the content. Successful exploitation may lead to arbitrary code execution in the context of the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High). All devices running iOS or iPadOS before 15.3.1, macOS Monterey before 12.2.1, or Safari before 15.3 are affected, which effectively means the broad Apple user base at the time of disclosure. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-11 and carries a 16.2% EPSS probability of exploitation in the next 30 days (97th percentile).

Do: Update iPhones and iPads to iOS/iPadOS 15.3.1, Macs to macOS Monterey 12.2.1, and Safari to version 15.3 (builds 16612.4.9.1.8 or 15612.4.9.1.8), per Apple's vendor instructions. Inventory for devices still on pre-patch versions, prioritizing user workstations and mobile devices that browse web or HTML email content, since WebKit loads content automatically. Note the vulnerability is listed in CISA's KEV catalog with 'apply updates per vendor instructions' as the required action, so patching is the only reliable mitigation.

8.816% KEV
  • Apple iOS (iPhone OS) prior to iOS 15.3.1
  • Apple iPadOS prior to iPadOS 15.3.1
  • Apple macOS (Monterey) prior to macOS Monterey 12.2.1
  • +1 more
mass≈1 billion+ Apple devices (WebKit is the system web engine on every iPhone, iPad, and Mac)
CVE-2022-22675
+1 in the same advisory: …22674
Out-of-Bounds Write in Apple macOS/iOS Kernel Allows Arbitrary Code Execution

CVE-2022-22675 is an out-of-bounds write vulnerability (CWE-787) in the Apple kernel, addressed through improved bounds checking. It is triggered locally — the CVSS vector shows a local attack vector with user interaction, meaning an application running on the device can trigger the memory corruption. Successful exploitation allows an application to execute arbitrary code with kernel privileges, giving the attacker full control over the affected device. Users of iPhone, iPad, Mac, Apple TV, and Apple Watch running versions prior to the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-04.

Do: Update to iOS/iPadOS 15.4.1, macOS Monterey 12.3.1 or macOS Big Sur 11.6.6, tvOS 15.5, and watchOS 8.6 as required by CISA. Because the flaw is exploited in the wild and requires only a malicious local application, prioritize patching user-facing iPhone, iPad, and Mac fleets first. There is no public PoC; verify installed OS versions on managed devices and confirm remediation after the updates are applied.

7.8
group max
12% KEV
  • apple iphone_os (iOS) prior to 15.4.1
  • apple ipados prior to 15.4.1
  • apple macos (Big Sur) prior to 11.6.6
  • +3 more
mass≈1 billion+ active Apple devices across iPhone, iPad, Mac, Apple TV, and Apple Watch
Full article276 words · extracted from therecord.media · click to collapse

Apple published two notices on Thursday about two zero-day vulnerabilities affecting Macs, iPhones and iPads.

Apple released fixes for CVE-2022-22675 and CVE-2022-22674, both of which were submitted by anonymous researchers.

“Apple is aware of a report that this issue may have been actively exploited,” the tech giant said of both vulnerabilities.

CVE-2022-22675 relates to an out-of-bounds write issue affecting the AppleAVD media decoder. Apple said it was addressed with improved bounds checking.

The company explained that the vulnerability would allow an attacker to take over a device and execute arbitrary code with kernel privileges.

CVE-2022-22674 is a similar out-of-bounds read issue affecting the Intel Graphics Driver that “may lead to the disclosure of kernel memory and was addressed with improved input validation.”

For Macs, the update is included in macOS Monterey 12.3.1. iPhones and iPads have the update in iOS 15.4.1 and iPadOS 15.4.1.

The fix is for iPhone 6s and later, all iPad Pro models, iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).

Apple declined to comment further about reports of the zero-days being exploited in the wild.

Apple has already patched three zero-days this year and patched at least 17 throughout 2021.

CVEPatch DateDescription
CVE-2022-22587January 27A memory corruption issue affecting iOS, iPadOS, and macOS Monterey.
CVE-2022-22594January 27A cross-origin issue affecting iOS, iPadOS, watchOS, tvOS, and macOS Monterey.
CVE-2022-22620February 10A use after free issue affecting iOS, iPadOS, and macOS Monterey.
CVE-2022-22675March 31An out-of-bounds write issue affecting iOS, iPadOS, and macOS Monterey.
CVE-2022-22674March 31An out-of-bounds read issue affecting macOS Monterey.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-releases-fixes-for-two-zero-days-affecting-macs-iphones-and-ipads