CERT-In Vulnerability Note
CIVN-2022-0312
Multiple Vulnerabilities in Apple iOS and iPadOS
Original Issue Date:July 29, 2022
Severity Rating: HIGH
Software Affected
- Apple iOS and iPadOS versions prior to 15.6
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could be exploited by a remote attacker to execute arbitrary code, bypass security restrictions and cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in Apple iOS and iPadOS due to out-of-bounds write in Audio, GPU Drivers, ICU and WebKit; buffer overflow in AppleAVD; authorization issue in AppleMobileFileIntegrity; logic issue in File System Events, Home, ImageIO, Kernel and PluginKit; memory corruption in GPU Drivers, IOMobileFrameBuffer and WebRTC; information disclosure in iCloud Photo Library; out-of-bounds read in ImageIO and Kernel; memory initialization in libxml2; type confusion in multi-touch. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a maliciously crafted web content.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, cause denial of service condition and bypass security on the targeted system.
Solution
Apply appropriate patches as mentioned in the
Apple Security Updates
Vendor Information
Apple
https://support.apple.com/en-us/HT213346
References
Apple
https://support.apple.com/en-us/HT213346
CVE Name
CVE-2022-32832
CVE-2022-32788
CVE-2022-32824
CVE-2022-32826
CVE-2022-32845
CVE-2022-32840
CVE-2022-32829
CVE-2022-32810
CVE-2022-32820
CVE-2022-32825
CVE-2022-32828
CVE-2022-32839
CVE-2022-32819
CVE-2022-32793
CVE-2022-32821
CVE-2022-32855
CVE-2022-32849
CVE-2022-32787
CVE-2022-32841
CVE-2022-32802
CVE-2022-32830
CVE-2022-32785
CVE-2022-26768
CVE-2022-32813
CVE-2022-32815
CVE-2022-32817
CVE-2022-32844
CVE-2022-32847
CVE-2022-26981
CVE-2022-32823
CVE-2022-32814
CVE-2022-32838
CVE-2022-32784
CVE-2022-32857
CVE-2022-32816
CVE-2022-32792
CVE-2022-2294
CVE-2022-32837
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|