CERT-In Vulnerability Note
CIVN-2022-0305
Multiple vulnerabilities in Apple Watch
Original Issue Date:July 22, 2022
Severity Rating: HIGH
Software Affected
- Apple watchOS versions prior to 8.7
Overview
Multiple vulnerabilities have been reported in Apple watch which could allow an attacker to execute arbitrary code and bypass security restriction on the targeted system.
Description
These vulnerabilities exist in Apple watch due to buffer overflow in AppleAVD component; an authorization issue in AppleMobileFileIntegrity component; out-of-bounds write in Audio, ICU and WebKit component; type confusion in Multi-Touch component; Multiple out-of-bounds write and memory corruption in GPU Drivers component; out-of-bounds read in Kernel component; and memory initialization in libxml2 component. A remote attacker could exploit these vulnerabilities by sending a specially-crafted request.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code and bypass security restriction on the targeted system.
Solution
Apply appropriate patches as mentioned in the
Apple Security Updates
Vendor Information
Apple
https://support.apple.com/en-us/HT213340
References
Apple
https://support.apple.com/en-us/HT213340
CVE Name
CVE-2022-32841
CVE-2022-32847
CVE-2022-32792
CVE-2022-32816
CVE-2022-32857
CVE-2022-32814
CVE-2022-32823
CVE-2022-26981
CVE-2022-32844
CVE-2022-32817
CVE-2022-32815
CVE-2022-32813
CVE-2022-32787
CVE-2022-32832
CVE-2022-32821
CVE-2022-32793
CVE-2022-32819
CVE-2022-32839
CVE-2022-32825
CVE-2022-32820
CVE-2022-32810
CVE-2022-32840
CVE-2022-32845
CVE-2022-32826
CVE-2022-32824
CVE-2022-32788
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|