CVE-2022-32911

HIGH

iPadOS < 15.7 - Out-of-bounds Write

Title source: llm
STIX 2.1

Description

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.

References (10)

Core 10
Core References
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/41
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213443
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213444
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213445
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213446
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213486
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213487
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213488

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (5)
apple/ipados < 15.7
apple/iphone_os < 15.7
apple/macos 11.0 - 11.7
apple/tvos < 16.0
apple/watchos < 9.0
Published Sep 20, 2022
Tracked Since Feb 18, 2026