CVE-2022-42864

HIGH EXPLOITED

iPadOS < 15.7.2 - Race Condition Leading to Arbitrary Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-42864 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Muirey03.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2022-42864, targeting Apple's HIDDriverKit. The code demonstrates the creation of a fake HID device and user client to interact with the HID interface, potentially leading to privilege escalation or arbitrary code execution in the kernel.

Description

A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

Exploits (1)

nomisec WORKING POC 66 stars
by Muirey03 · dos
https://github.com/Muirey03/CVE-2022-42864

This repository contains a proof-of-concept exploit for CVE-2022-42864, targeting Apple's HIDDriverKit. The code demonstrates the creation of a fake HID device and user client to interact with the HID interface, potentially leading to privilege escalation or arbitrary code execution in the kernel.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Apple HIDDriverKit (macOS)
No auth needed
Prerequisites: macOS system with vulnerable HIDDriverKit · Ability to load kernel extensions
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213530
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213531
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213532
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213533
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213534
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213535
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213536
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/20
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/21
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/25
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/23
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/26
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/24
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Dec/27

Scores

CVSS v3 7.0
EPSS 0.0086
EPSS Percentile 53.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2022-12-13
CWE
CWE-362
Status published
Products (6)
apple/ipados < 15.7.2
apple/iphone_os < 15.7.2
apple/macos 13.0
apple/macos < 11.7.2
apple/tvos < 16.2
apple/watchos < 9.2
Published Dec 15, 2022
Tracked Since Feb 18, 2026