Out-of-bounds write in macOS - CVE-2022-32894
Published: August 17, 2022 / Updated: August 24, 2022
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the OS kernel component. A local application can trigger an out-of-bounds write error and execute arbitrary code on the system with kernel privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
iPadOS
watchOS
How to mitigate CVE-2022-32894
Apple iOS - addressed in versions 12.5.6 16H71, 15.6.1 19G82
iPadOS - update to 15.6.1 19G82
watchOS - update to 9.0 20R361