Security News > 2022 > January > Apple Releases iOS and macOS Updates to Patch Actively Exploited 0-Day Vulnerability
Tracked as CVE-2022-22587, the vulnerability relates to a memory corruption issue in the IOMobileFrameBuffer component that could be abused by a malicious application to execute arbitrary code with kernel privileges.
The iPhone maker said it's "Aware of a report that this issue may have been actively exploited," adding it addressed the issue with improved input validation.
CVE-2022-22585 - A path validation issue in iCloud that could be exploited be a rogue application to access a user's files.
CVE-2022-22591 - A memory corruption issue in Intel Graphics Driver that could be abused by a malicious application to execute arbitrary code with kernel privileges.
CVE-2022-22593 - A buffer overflow issue in Kernel that could be abused by a malicious application to execute arbitrary code with kernel privileges.
The updates are available for iPhone 6s and later, iPad Pro, iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, iPod touch, and macOS devices running Big Sur, Catalina, and Monterey.
News URL
https://thehackernews.com/2022/01/apple-releases-ios-and-ipados-updates.html
Related news
- Oracle warns that macOS 14.4 update breaks Java on Apple CPUs (source)
- Hardware-level Apple Silicon vulnerability can leak cryptographic keys (source)
- New "GoFetch" Vulnerability in Apple M-Series Chips Leaks Secret Encryption Keys (source)
- New GoFetch Vulnerability in Apple’s M Chips Allows Secret Keys Leak on Compromised Computers (source)
- Hardware Vulnerability in Apple’s M-Series Chips (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-18 | CVE-2022-22593 | Classic Buffer Overflow vulnerability in Apple products A buffer overflow issue was addressed with improved memory handling. | 9.3 |
2022-03-18 | CVE-2022-22591 | Out-of-bounds Write vulnerability in Apple Macos 12.0.0/12.0.1 A memory corruption issue was addressed with improved memory handling. | 9.3 |
2022-03-18 | CVE-2022-22587 | Out-of-bounds Write vulnerability in Apple Ipados and Iphone OS A memory corruption issue was addressed with improved input validation. | 10.0 |
2022-03-18 | CVE-2022-22585 | Link Following vulnerability in Apple products An issue existed within the path validation logic for symlinks. | 5.0 |