Executive brief
An out-of-bounds write vulnerability in the Apple iOS and iPadOS kernel allows a local application to execute arbitrary code with kernel privileges. The issue was addressed through improved bounds checking in multiple Apple operating systems.
Affected products
- Apple iOS < 15.7.1, 16.0
- Apple iPadOS < 15.7.1
- Apple macOS Monterey < 12.6.1
- Apple tvOS < 16.1
- Apple watchOS < 9.1
Timeline
- 2022-10-25: disclosed: Initial publication and CISA KEV addition date.
- 2022-10-25: kev added
- 2022-11-01: advisory: NVD Published Date.
- 2022-10-25: exploited: Apple reported awareness of active exploitation.