Buffer overflow in Apple iOS and iPadOS - CVE-2022-22587

 

Buffer overflow in Apple iOS and iPadOS - CVE-2022-22587

Published: January 26, 2022


Vulnerability identifier: #VU60033
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22587
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a malicious application to execute arbitrary code with elevated privileges.

The vulnerability exists due to a boundary error within the IOMobileFrameBuffer subsystem. A malicious application can trigger buffer overflow and execute arbitrary code with kernel privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Apple iOS
iPadOS
macOS

How to mitigate CVE-2022-22587

Install updates from vendor's website.

Apple iOS - update to 15.3 19D50
iPadOS - update to 15.3 19D50
macOS - addressed in versions 11.6.3 20G415, 12.2 21D49

External References

Related Security Bulletins