Junglewise Threat Intelligence

CVE-2022-32894: Apple iOS and macOS Out-of-Bounds Write Vulnerability

CVE-2022-32894 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-08-18

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple macOS Monterey, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

An out-of-bounds write vulnerability in Apple iOS, iPadOS, and macOS allows an application to execute arbitrary code with kernel privileges. The issue was addressed through improved bounds checking in the kernel component.

Affected products

  • Apple iOS < 15.6.1
  • Apple iPadOS < 15.6.1
  • Apple macOS Monterey < 12.5.1
  • Apple macOS Big Sur 11.0 to < 11.7
  • Apple watchOS < 9.0

Timeline

  • 2022-08-18: disclosed
  • 2022-08-18: patched: Fixed in iOS 15.6.1, iPadOS 15.6.1, and macOS Monterey 12.5.1
  • 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-18: exploited: Apple reported awareness of active exploitation at time of publication.

Related threats