CERT-In Vulnerability Note
CIVN-2022-0236
Multiple Vulnerabilities in Apple iOS and iPadOS
Original Issue Date:May 18, 2022
Severity Rating: HIGH
Software Affected
- Apple iOS and iPadOS versions prior to 15.5
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could be exploited by a remote attacker to execute arbitrary code, bypass security restrictions and cause denial of service condition on a targeted system.
Description
These vulnerabilities exists in Apple iOS and iPadOS due to use after free in AppleAVD, WebKit, libxml2 & Kernel component; memory corruption in AppleGraphicsControl, WebKit, IOMobileFrameBuffer, IOSurfaceAccelerator, Kernel, Wi-Fi & GPU Drivers; out-of-bounds write in AVEVideoEncoder; out-of-bounds access in DriverKit; integer overflow in ImageIO; race condition in IOKit & Kernel; access issue in LaunchServices; logic issues in Safari Private Browsing & WebRTC; certificate parsing in Security; authorization issues in Shortcuts and improved checks in Wi-Fi & Notes. A remote attacker can exploit these vulnerabilities by persuading a victim to visit a maliciously crafted web content.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, cause denial of service condition and bypass security on the targeted system.
Solution
Apply appropriate updates as mentioned in Apple Security updates:
https://support.apple.com/en-us/HT213258
Vendor Information
Apple
https://support.apple.com/en-us/HT213258
References
Apple
https://support.apple.com/en-us/HT213258
CVE Name
CVE-2022-26702
CVE-2022-26751
CVE-2022-26736
CVE-2022-26737
CVE-2022-26738
CVE-2022-26739
CVE-2022-26740
CVE-2022-26763
CVE-2022-26744
CVE-2022-26711
CVE-2022-26701
CVE-2022-26768
CVE-2022-26771
CVE-2022-26714
CVE-2022-26757
CVE-2022-26764
CVE-2022-26765
CVE-2022-26706
CVE-2022-23308
CVE-2022-22673
CVE-2022-26731
CVE-2022-26766
CVE-2022-26703
CVE-2022-26700
CVE-2022-26709
CVE-2022-26710
CVE-2022-26717
CVE-2022-26716
CVE-2022-26719
CVE-2022-22677
CVE-2022-26745
CVE-2022-26760
CVE-2015-4142
CVE-2022-26762
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|