Security News > 2022 > October > Apple fixes exploited iOS, iPadOS zero-day (CVE-2022-42827)

Apple fixes exploited iOS, iPadOS zero-day (CVE-2022-42827)
2022-10-25 08:44

For the ninth time this year, Apple has released fixes for a zero-day vulnerability exploited by attackers to compromise iPhones.

CVE-2022-42827 is an out-of-bounds write issue in the iOS and iPadOS kernel, which can be exploited to allow a malicious application to execute arbitrary code with kernel privileges.

iOS 16.1 and iPadOS 16 also come with fixes for 19 additional CVE-numbered security issues, including a flaw in the Bluetooth component that could allow an app to record audio using a pair of connected AirPods, and many other code execution holes.

Mac users, whether they are running macOS Big Sur, Monterey, or Ventura, have also security updates available.

Ventura's is particularly sizeable, with fixes for 113 issues.

Safari, tvOS and watchOS security updates have also been released.


News URL

https://www.helpnetsecurity.com/2022/10/25/cve-2022-42827/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-11-01 CVE-2022-42827 Out-of-bounds Write vulnerability in Apple products
An out-of-bounds write issue was addressed with improved bounds checking.
local
low complexity
apple CWE-787
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 68 212 1433 2208 257 4110