Junglewise Threat Intelligence

CVE-2022-42827: Apple iOS and iPadOS Out-of-Bounds Write Vulnerability

CVE-2022-42827 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-10-25

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple Tvos, Apple iPadOS, Apple macOS Monterey. Vendors: Cisco, Apple.

Executive brief

An out-of-bounds write vulnerability in the Apple iOS and iPadOS kernel allows a local application to execute arbitrary code with kernel privileges. The issue was addressed through improved bounds checking in multiple Apple operating systems.

Affected products

  • Apple iOS < 15.7.1, 16.0
  • Apple iPadOS < 15.7.1
  • Apple macOS Monterey < 12.6.1
  • Apple tvOS < 16.1
  • Apple watchOS < 9.1

Timeline

  • 2022-10-25: disclosed: Initial publication and CISA KEV addition date.
  • 2022-10-25: kev added
  • 2022-11-01: advisory: NVD Published Date.
  • 2022-10-25: exploited: Apple reported awareness of active exploitation.

Related threats