Buffer overflow in Apple iOS and iPadOS - CVE-2022-22587
Published: January 26, 2022
Vulnerability details
The vulnerability allows a malicious application to execute arbitrary code with elevated privileges.
The vulnerability exists due to a boundary error within the IOMobileFrameBuffer subsystem. A malicious application can trigger buffer overflow and execute arbitrary code with kernel privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
iPadOS
macOS
How to mitigate CVE-2022-22587
iPadOS - update to 15.3 19D50
macOS - addressed in versions 11.6.3 20G415, 12.2 21D49