CERT-In Vulnerability Note
CIVN-2022-0408
Multiple Vulnerabilities in Apple iOS
Original Issue Date:October 26, 2022
Severity Rating: HIGH
Software Affected
- Apple iOS 16.1 and iPadOS versions prior to 16
- iPhone 8 and later
- iPad Pro (all models)
- iPad Air 3rd generation and later
- iPad 5th generation and later
- iPad mini 5th generation and later
- Apple iOS versions prior to 16.0.3
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could allow a remote attacker to gain access to sensitive information, execute arbitrary code, spoofing of the interface address or denial of service conditions on the targeted system.
Description
These vulnerabilities exist in Apple iOS and iPadOS due to Improper security restrictions in AppleMobileFileIntegrity component; Improper bounds check in AVEVideoEncoder component; Improper validation in CFNetwork component; Improper entitlement in Core Bluetooth component; Improper memory handling in GPU Drivers component; Memory corruption issue in IOHIDFamily component; Use after free issue and Race condition issue in IOKit component; Improper memory handling and Out-of-bounds write issue in Kernel component; Use after free issue, Improper memory handling and Race condition issue in PPP component; Improper security restrictions and Improper path validation in Sandbox component; Improper UI handling, Type confusion issue and Logic issue in Webkit component; Use-after-free error in WebKit PDF component; Improper input validation in Mail component. A remote attacker could exploit these vulnerabilities by persuading the victim to open a specially crafted file or application. Successful exploitation of these vulnerabilities could allow the attacker to gain access to sensitive information, execute arbitrary code, spoofing of the interface address or denial of service conditions on the targeted system.
Note: The vulnerability (CVE-2022-42827) is being exploited in the wild. Users are advised to apply patches urgently.
Solution
Apply appropriate software updates as mentioned in the Apple Security updates
https://support.apple.com/en-us/HT213480
Vendor Information
Apple
https://support.apple.com/en-us/HT213480
https://support.apple.com/en-us/HT213489
References
Apple
https://support.apple.com/en-us/HT213480
https://support.apple.com/en-us/HT213489
CVE Name
CVE-2022-42825
CVE-2022-32940
CVE-2022-42813
CVE-2022-32946
CVE-2022-32947
CVE-2022-42820
CVE-2022-42806
CVE-2022-32924
CVE-2022-42808
CVE-2022-42827
CVE-2022-42829
CVE-2022-42830
CVE-2022-42831
CVE-2022-42832
CVE-2022-42811
CVE-2022-32938
CVE-2022-42799
CVE-2022-42823
CVE-2022-42824
CVE-2022-32922
CVE-2022-22658
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|