CVE-2022-32832

MEDIUM

iPadOS < 15.6 - Authenticated Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-32832. PoCs published by Muirey03, AkbarTrilaksana.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2022-32832, a race condition vulnerability in AppleAPFSUserClient::methodDeltaCreateFinalize. The exploit triggers a double-free by racing two calls to the vulnerable method, leading to a kernel panic on vulnerable macOS versions.

Description

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.

Exploits (2)

nomisec WORKING POC 96 stars
by Muirey03 · poc
https://github.com/Muirey03/CVE-2022-32832

This repository contains a functional proof-of-concept exploit for CVE-2022-32832, a race condition vulnerability in AppleAPFSUserClient::methodDeltaCreateFinalize. The exploit triggers a double-free by racing two calls to the vulnerable method, leading to a kernel panic on vulnerable macOS versions.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Apple APFS (macOS 12.5 beta 2 and earlier)
Auth required
Prerequisites: Root privileges · Vulnerable macOS version
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 2 stars
by AkbarTrilaksana · poc
https://github.com/AkbarTrilaksana/CVE-2022-32832

This repository contains a functional proof-of-concept exploit for CVE-2022-32832, a race condition vulnerability in AppleAPFSUserClient::methodDeltaCreateFinalize. The exploit triggers a double-free by racing two calls to the vulnerable method, leading to a kernel panic on vulnerable macOS versions.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Apple APFS (macOS 12.5 beta 2 and earlier)
Auth required
Prerequisites: Root privileges · Unmounted volume for delta creation
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213345
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213340
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213342
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213346
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213344
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213343

Scores

CVSS v3 6.7
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (7)
apple/ipados < 15.6
apple/iphone_os < 15.6
apple/mac_os_x 10.15.7 security_update_2020-001 (12 CPE variants)
apple/macos 10.15.7 (2 CPE variants)
apple/macos < 10.15.7
apple/tvos < 15.6
apple/watchos < 8.7
Published Sep 23, 2022
Tracked Since Feb 18, 2026