CERT-In Vulnerability Note
CIVN-2022-0313
Multiple Vulnerabilities in Apple macOS
Original Issue Date:July 29, 2022
Severity Rating: HIGH
Software Affected
- Apple macOS Catalina prior to security update 2022-005
- Apple macOS Big Sur versions prior to 11.6.8
- Apple macOS Monterey versions prior to 12.5
Overview
Multiple vulnerabilities have been reported in Apple macOS which could be exploited by a remote attacker to execute arbitrary code, bypass security restrictions and cause denial of service conditions on the targeted system.
Description
These vulnerabilities exist in Apple macOS due to out-of-bounds read in AppleScript, SMB and Kernel; out-of-bounds write in Audio, ICU, PS Normalizer, GPU Drivers, SMB and WebKit; authorization issue in AppleMobileFileIntegrity; information disclosure in Calendar and iCloud Photo Library; logic issue in File System Events, PluginKit, Windows Server and Automation; memory corruption in Intel Graphics Driver, GPU Drivers, SMB and WebRTC; type confusion in multi-touch; memory initialization in libxml2. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a maliciously crafted web content.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code, cause denial of service conditions and bypass security restrictions on the targeted system.
Solution
Apply appropriate patches as mentioned in the
Apple Security Updates
Vendor Information
Apple
https://support.apple.com/en-us/HT213343
https://support.apple.com/en-us/HT213344
https://support.apple.com/en-us/HT213345
References
Apple
https://support.apple.com/en-us/HT213343
https://support.apple.com/en-us/HT213344
https://support.apple.com/en-us/HT213345
CVE Name
CVE-2022-32832
CVE-2022-32826
CVE-2022-32797
CVE-2022-32853
CVE-2022-32851
CVE-2022-32831
CVE-2022-32820
CVE-2022-32805
CVE-2022-32849
CVE-2022-32839
CVE-2022-32781
CVE-2022-32819
CVE-2022-32787
CVE-2022-32785
CVE-2022-32812
CVE-2022-32811
CVE-2022-32815
CVE-2022-32813
CVE-2022-32823
CVE-2022-32786
CVE-2022-32800
CVE-2022-32838
CVE-2022-32843
CVE-2022-32842
CVE-2022-32799
CVE-2022-32857
CVE-2022-32807
CVE-2022-26704
CVE-2022-32834
CVE-2021-4136
CVE-2021-4166
CVE-2021-4173
CVE-2021-4187
CVE-2021-4192
CVE-2021-4193
CVE-2021-46059
CVE-2022-0128
CVE-2022-32847
CVE-2022-32825
CVE-2022-0156
CVE-2022-0158
CVE-2022-32848
CVE-2022-32810
CVE-2022-32840
CVE-2022-32845
CVE-2022-32852
CVE-2022-32789
CVE-2022-32828
CVE-2022-32793
CVE-2022-32821
CVE-2022-32841
CVE-2022-32785
CVE-2022-32817
CVE-2022-32829
CVE-2022-26981
CVE-2022-32814
CVE-2022-32796
CVE-2022-32798
CVE-2022-32818
CVE-2022-32801
CVE-2021-28544
CVE-2022-24070
CVE-2022-29046
CVE-2022-29048
CVE-2022-32816
CVE-2022-32792
CVE-2022-2294
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|