Out-of-bounds write in macOS - CVE-2022-32894

 

Out-of-bounds write in macOS - CVE-2022-32894

Published: August 17, 2022 / Updated: August 24, 2022


Vulnerability identifier: #VU66586
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32894
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the OS kernel component. A local application can trigger an out-of-bounds write error and execute arbitrary code on the system with kernel privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

macOS
Apple iOS
iPadOS
watchOS

How to mitigate CVE-2022-32894

Install updates from vendor's website.

macOS - addressed in versions 12.5.1 21G83, 11.7 20G817
Apple iOS - addressed in versions 12.5.6 16H71, 15.6.1 19G82
iPadOS - update to 15.6.1 19G82
watchOS - update to 9.0 20R361

External References

Related Security Bulletins