Buffer overflow in macOS - CVE-2022-32832
Published: July 20, 2022 / Updated: July 24, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the AppleAPFSUserClient::methodDeltaCreateFinalize() method in APFS. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code with root privileges.
Affected software
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2022-32832
iPadOS - update to 15.6 19G71
Apple iOS - update to 15.6 19G71
tvOS - update to 15.6 19M65