Executive brief
A memory corruption vulnerability in the Apple IOMobileFrameBuffer component allows a malicious application to execute arbitrary code with kernel privileges. The issue stems from insufficient input validation and has been reported as being actively exploited in the wild.
Affected products
- Apple iOS before 15.3
- Apple iPadOS before 15.3
- Apple macOS Big Sur before 11.6.3
- Apple macOS Monterey before 12.2
Timeline
- 2022-01-28: disclosed: Initial publication date
- 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-28: patched: Fixed in iOS 15.3, iPadOS 15.3, macOS Big Sur 11.6.3, and macOS Monterey 12.2
- 2022-01-28: exploited: Apple reported awareness of active exploitation at time of disclosure.