Junglewise Threat Intelligence

CVE-2022-32917: Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability

CVE-2022-32917 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-09-14

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS, Apple macOS Monterey. Vendors: Apple, Cisco.

Executive brief

An out-of-bounds write vulnerability in the Apple kernel allows an application to execute arbitrary code with kernel privileges. The issue was addressed through improved bounds checking in multiple Apple operating systems.

Affected products

  • Apple iOS Before 15.7, 16
  • Apple iPadOS Before 15.7
  • Apple macOS Monterey Before 12.6
  • Apple macOS Big Sur 11.0 before 11.7

Timeline

  • 2022-09-14: disclosed
  • 2022-09-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-14: patched: Fixed in macOS Monterey 12.6, iOS 15.7, iPadOS 15.7, iOS 16, and macOS Big Sur 11.7
  • exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats