Apple releases emergency patch for two iPhone, Mac zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22587 | Memory Corruption in Apple iOS, iPadOS, and macOS Allows Kernel-Privilege Code Execution CVE-2022-22587 is a memory corruption flaw (CWE-787, out-of-bounds write) in Apple's operating systems that Apple addressed with improved input validation. It is triggered by a malicious application already running on a vulnerable device, which can exploit the corruption to execute arbitrary code with kernel privileges — the highest privilege level of the OS. All iPhones and iPads running iOS/iPadOS versions earlier than 15.3 and Macs running macOS Monterey earlier than 12.2 or Big Sur earlier than 11.6.3 are affected. Apple reported the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28; EPSS rates it at 11.6% probability of exploitation in the next 30 days (96th percentile). It was one of two actively exploited Apple zero-days patched in Apple's January 2022 emergency updates. Do: Update iPhones and iPads to iOS/iPadOS 15.3 and Macs to macOS Monterey 12.2 or Big Sur 11.6.3 (or later). Inventory managed fleets for devices below these versions, since the flaw is exploited in the wild and CISA KEV requires applying vendor updates. Until devices are patched, limit exposure by avoiding installation of untrusted applications on vulnerable iPhones, iPads, and Macs. | 9.8 | 12% | KEV |
| mass>1 billion active Apple devices (all iPhones, iPads, and Macs below the fixed versions) | |
| CVE-2022-22594 | A cross-origin issue in the IndexDB API was addressed with improved input validation. A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2022-22620 | WebKit Use-After-Free (CVE-2022-22620) Enables RCE on iOS, iPadOS, and macOS CVE-2022-22620 is a use-after-free (CWE-416) in Apple's WebKit browser engine, the component that renders web content on iPhones, iPads, Macs, and Safari. An attacker triggers it by getting a victim to process maliciously crafted web content, such as visiting an attacker-controlled webpage, requiring no privileges and only user interaction with the content. Successful exploitation may lead to arbitrary code execution in the context of the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High). All devices running iOS or iPadOS before 15.3.1, macOS Monterey before 12.2.1, or Safari before 15.3 are affected, which effectively means the broad Apple user base at the time of disclosure. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-11 and carries a 16.2% EPSS probability of exploitation in the next 30 days (97th percentile). Do: Update iPhones and iPads to iOS/iPadOS 15.3.1, Macs to macOS Monterey 12.2.1, and Safari to version 15.3 (builds 16612.4.9.1.8 or 15612.4.9.1.8), per Apple's vendor instructions. Inventory for devices still on pre-patch versions, prioritizing user workstations and mobile devices that browse web or HTML email content, since WebKit loads content automatically. Note the vulnerability is listed in CISA's KEV catalog with 'apply updates per vendor instructions' as the required action, so patching is the only reliable mitigation. | 8.8 | 16% | KEV |
| mass≈1 billion+ Apple devices (WebKit is the system web engine on every iPhone, iPad, and Mac) | |
| CVE-2022-22675 +1 in the same advisory: …22674 | Out-of-Bounds Write in Apple macOS/iOS Kernel Allows Arbitrary Code Execution CVE-2022-22675 is an out-of-bounds write vulnerability (CWE-787) in the Apple kernel, addressed through improved bounds checking. It is triggered locally — the CVSS vector shows a local attack vector with user interaction, meaning an application running on the device can trigger the memory corruption. Successful exploitation allows an application to execute arbitrary code with kernel privileges, giving the attacker full control over the affected device. Users of iPhone, iPad, Mac, Apple TV, and Apple Watch running versions prior to the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-04. Do: Update to iOS/iPadOS 15.4.1, macOS Monterey 12.3.1 or macOS Big Sur 11.6.6, tvOS 15.5, and watchOS 8.6 as required by CISA. Because the flaw is exploited in the wild and requires only a malicious local application, prioritize patching user-facing iPhone, iPad, and Mac fleets first. There is no public PoC; verify installed OS versions on managed devices and confirm remediation after the updates are applied. | 7.8 group max | 12% | KEV |
| mass≈1 billion+ active Apple devices across iPhone, iPad, Mac, Apple TV, and Apple Watch | |
| CVE-2022-32893 +1 in the same advisory: …32894 | Out-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known. Do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted. | 8.8 group max | 10% | KEV |
| masshundreds of millions of devices (Apple's active iPhone/Mac installed base plus Safari/WebKit users) |
Full article637 words · extracted from therecord.media · click to collapse
Apple said hackers are actively exploiting two zero-day vulnerabilities in iPhones, iPads and Macs. In an emergency patch announced this week, Apple released very little information about the bugs, only saying they were submitted anonymously and giving them CVE entries – CVE-2022-32894 and CVE-2022-32893. Apple said some iPod models, the iPhone 6S and later models, several models of the iPad, all iPad Pro models and the iPad Air 2 as well as all Mac computers running MacOS Monterey are affected by the bugs. The vulnerabilities give an attacker the highest privileges in macOS, iPadOS, and iOS — effectively full control of a device. Robert Nickle, staff security intelligence engineer at Lookout, explained that the first bug is in “webkit” — the engine of the web browser on iOS. This is likely used as the entry point for an attack, meaning the attack is likely to be initiated by visiting a malicious website, Nickle said. “The second vulnerability mentioned is in the kernel which then allows for a complete system take over,” he explained. The company did not respond to requests for comment about the vulnerabilities. Bugcrowd founder Casey Ellis said the vulnerabilities Apple described are “versatile to an attacker” and said an emergency patch was warranted considering an exploit already appears to be in active use. Others, like Digital Shadows’ Rick Holland, noted that Apple should provide more details in their security updates to give defenders additional context that would allow them to better mitigate the risk. “It is never reassuring to see the phrase 'execute arbitrary code with kernel privileges.' The WebKit component is also particularly problematic, as it is the browser engine across all Apple software; Apple users should patch now,” Holland said. “Enterprises still need to be concerned because even if you can patch the corporate devices, you can't update all the personal devices employees might use. A compromised personal device could result in initial access to the corporate environment.” ATTENTION The zero-days would be the sixth and seventh vulnerabilities disclosed by Apple this year. The company reported 17 zero-days in 2021. Netenrich’s John Bambenek added that any vulnerability letting attackers get full privilege on an iPhone is “always very serious and should be addressed immediately.” “My hunch is that there were some targeted attacks against some group of people that got noticed and I imagine we’ll here more in the coming days,” he said. Last month, Apple introduced a new "Lockdown Mode" designed to stop spyware sold to governments. Apple has in recent years been at war with spyware firms around the world that make millions from weaponizing zero-day vulnerabilities in the company's devices.
Apple found two 0-days actively in use that could effectively give attackers full access to device.
For most folks: update software by end of day
If threat model is elevated (journalist, activist, targeted by nation states, etc): update now https://t.co/BUEn08260XCVE Patch Date Description CVE-2022-22587 January 27 A memory corruption issue affecting iOS, iPadOS, and macOS Monterey. CVE-2022-22594 January 27 A cross-origin issue affecting iOS, iPadOS, watchOS, tvOS, and macOS Monterey. CVE-2022-22620 February 10 A use after free issue affecting iOS, iPadOS, and macOS Monterey. CVE-2022-22675 March 31 An out-of-bounds write issue affecting iOS, iPadOS, and macOS Monterey. CVE-2022-22674 March 31 An out-of-bounds read issue affecting macOS Monterey. CVE-2022-32893 August 17 An out-of-bounds write issue affecting iOS, iPadOS, and macOS Monterey. CVE-2022-32894 August 17 An out-of-bounds write issue affecting iOS, iPadOS, and macOS Monterey.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-releases-emergency-patch-for-two-iphone-mac-zero-day-vulnerabilities-being-exploited