Apple iOS The iOS Operating System used by iPhones.
By the Year
In 2023 there have been 0 vulnerabilities in Apple iOS . Last year iOS had 242 security vulnerabilities published. Right now, iOS is on track to have less security vulnerabilities in 2023 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 0 | 0.00 |
2022 | 242 | 7.09 |
2021 | 382 | 7.01 |
2020 | 252 | 7.09 |
2019 | 348 | 7.49 |
2018 | 98 | 7.37 |
It may take a day or so for new iOS vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apple iOS Security Vulnerabilities
A memory corruption issue was addressed with improved state management
CVE-2022-42863
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
The issue was addressed with improved handling of caches
CVE-2022-42866
5.5 - Medium
- December 15, 2022
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
A use after free issue was addressed with improved memory management
CVE-2022-42867
8.8 - High
- December 15, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A logic issue was addressed with improved state management
CVE-2022-46692
5.5 - Medium
- December 15, 2022
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
An issue existed in the parsing of URLs
CVE-2022-42837
9.8 - Critical
- December 15, 2022
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.
The issue was addressed with improved memory handling
CVE-2022-42842
9.8 - Critical
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
This issue was addressed with improved data protection
CVE-2022-42843
5.5 - Medium
- December 15, 2022
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
Exposure of Resource to Wrong Sphere
An access issue existed with privileged API calls
CVE-2022-42849
7.8 - High
- December 15, 2022
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
AuthZ
The issue was addressed with improved memory handling
CVE-2022-42851
5.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.
The issue was addressed with improved memory handling
CVE-2022-42852
6.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
The issue was addressed with improved memory handling
CVE-2022-42846
5.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.
The issue was addressed with improved memory handling
CVE-2022-42845
7.2 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-42844
8.6 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox.
The issue was addressed with improved memory handling
CVE-2022-42840
7.8 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
An integer overflow was addressed with improved input validation
CVE-2022-42805
7.8 - High
- December 15, 2022
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Integer Overflow or Wraparound
A memory corruption issue was addressed with improved input validation
CVE-2022-46700
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A memory corruption issue was addressed with improved state management
CVE-2022-46699
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A logic issue was addressed with improved checks
CVE-2022-46698
6.5 - Medium
- December 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
A memory corruption issue was addressed with improved input validation
CVE-2022-46696
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A spoofing issue existed in the handling of URLs
CVE-2022-46695
6.5 - Medium
- December 15, 2022
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
Clickjacking
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46694
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-42850
7.8 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
A logic issue was addressed with improved checks
CVE-2022-42848
7.8 - High
- December 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
An out-of-bounds read was addressed with improved bounds checking
CVE-2022-32948
7.8 - High
- December 15, 2022
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Out-of-bounds Read
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46693
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.
Memory Corruption
A memory consumption issue was addressed with improved memory handling
CVE-2022-46691
8.8 - High
- December 15, 2022
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46690
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
A race condition was addressed with improved state handling
CVE-2022-42864
7 - High
- December 15, 2022
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
An out-of-bounds read issue existed that led to the disclosure of kernel memory
CVE-2022-32916
5.5 - Medium
- December 15, 2022
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 16. An app may be able to disclose kernel memory.
Out-of-bounds Read
An out-of-bounds write was addressed with improved input validation
CVE-2022-32860
7.8 - High
- December 15, 2022
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
An issue existed with the file paths used to store website data
CVE-2022-32833
5.3 - Medium
- December 15, 2022
An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
Exposure of Resource to Wrong Sphere
The issue was addressed with improved memory handling
CVE-2022-46702
5.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.
A race condition was addressed with additional validation
CVE-2022-46689
7 - High
- December 15, 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
Multiple issues were addressed by removing the vulnerable code
CVE-2022-42859
5.5 - Medium
- December 15, 2022
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.
This issue was addressed by enabling hardened runtime
CVE-2022-42865
5.5 - Medium
- December 15, 2022
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
The issue was addressed with improved bounds checks
CVE-2022-46701
7.8 - High
- December 15, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.
Buffer Overflow
A type confusion issue was addressed with improved state handling
CVE-2022-42856
8.8 - High
- December 15, 2022
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Object Type Confusion
This issue was addressed by removing the vulnerable code
CVE-2022-42862
5.5 - Medium
- December 15, 2022
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.
This issue was addressed with improved checks
CVE-2022-42861
8.8 - High
- December 15, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.
A logic issue was addressed with improved state management
CVE-2022-42855
7.1 - High
- December 15, 2022
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
The issue was addressed with improved bounds checks
CVE-2022-32943
5.3 - Medium
- December 15, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
An access issue was addressed with additional sandbox restrictions on third-party apps
CVE-2022-32945
4.3 - Medium
- December 15, 2022
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
AuthZ
An issue was discovered in libxml2 before 2.10.3
CVE-2022-40304
7.8 - High
- November 23, 2022
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
XXE
An issue was discovered in libxml2 before 2.10.3
CVE-2022-40303
7.5 - High
- November 23, 2022
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
Integer Overflow or Wraparound
The issue was addressed with improved handling of caches
CVE-2022-32909
5.5 - Medium
- November 01, 2022
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app may be able to access user-sensitive data.
A logic issue was addressed with improved state management
CVE-2022-32875
5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6. An app may be able to read sensitive location information.
A logic issue was addressed with improved state management
CVE-2022-32870
2.4 - Low
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.
This issue was addressed with improved data protection
CVE-2022-32867
2.4 - Low
- November 01, 2022
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.
The issue was addressed with improved memory handling
CVE-2022-32865
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32947
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
This issue was addressed with improved entitlements
CVE-2022-32946
5.5 - Medium
- November 01, 2022
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.
A memory corruption issue was addressed with improved state management
CVE-2022-32944
7.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to execute arbitrary code with kernel privileges.
A use after free issue was addressed with improved memory management
CVE-2022-42829
6.7 - Medium
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Dangling pointer
The issue was addressed with improved bounds checks
CVE-2022-32941
9.8 - Critical
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A buffer overflow may result in arbitrary code execution.
Classic Buffer Overflow
The issue was addressed with improved bounds checks
CVE-2022-32940
7.8 - High
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved bounds checks
CVE-2022-32939
7.8 - High
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An app may be able to execute arbitrary code with kernel privileges.
A parsing issue in the handling of directory paths was addressed with improved path validation
CVE-2022-32938
5.3 - Medium
- November 01, 2022
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. A shortcut may be able to check the existence of an arbitrary path on the file system.
A lock screen issue was addressed with improved state management
CVE-2022-32935
4.6 - Medium
- November 01, 2022
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.
The issue was addressed with improved memory handling
CVE-2022-32932
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
A permissions issue was addressed with additional restrictions
CVE-2022-32929
5.5 - Medium
- November 01, 2022
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.7, iOS 16.1 and iPadOS 16. An app may be able to access iOS backups.
A logic issue was addressed with improved restrictions
CVE-2022-32928
5.3 - Medium
- November 01, 2022
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.
The issue was addressed with improved memory handling
CVE-2022-32927
7.5 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining a malicious Wi-Fi network may result in a denial-of-service of the Settings app.
The issue was addressed with improved bounds checks
CVE-2022-32926
6.7 - Medium
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16. An app with root privileges may be able to execute arbitrary code with kernel privileges.
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-32925
7.1 - High
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-32924
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.
A correctness issue in the JIT was addressed with improved checks
CVE-2022-32923
6.5 - Medium
- November 01, 2022
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.
The issue was addressed with improved memory handling
CVE-2022-42830
6.7 - Medium
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
A race condition was addressed with improved locking
CVE-2022-42831
6.4 - Medium
- November 01, 2022
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Race Condition
A race condition was addressed with improved locking
CVE-2022-42832
6.4 - Medium
- November 01, 2022
A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Race Condition
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-32888
8.8 - High
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-32889
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
An access issue was addressed with improvements to the sandbox
CVE-2022-32892
8.6 - High
- November 01, 2022
An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
A use after free issue was addressed with improved memory management
CVE-2022-32922
8.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
The issue was addressed with improved memory handling
CVE-2022-32898
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
A use after free issue was addressed with improved memory management
CVE-2022-32914
7.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
Dangling pointer
A use after free issue was addressed with improved memory management
CVE-2022-32903
7.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
Dangling pointer
A logic issue was addressed with improved state management
CVE-2022-32879
2.4 - Low
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, tvOS 16. A user with physical access to a device may be able to access contacts from the lock screen.
A memory consumption issue was addressed with improved memory handling
CVE-2022-42795
8.8 - High
- November 01, 2022
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
Memory Corruption
A logic issue was addressed with improved state management
CVE-2022-42790
5.5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. A user may be able to view restricted content from the lock screen.
This issue was addressed with improved data protection
CVE-2022-32918
5.5 - Medium
- November 01, 2022
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.
A use after free issue was addressed with improved memory management
CVE-2022-26717
8.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A type confusion issue was addressed with improved memory handling
CVE-2022-42823
8.8 - High
- November 01, 2022
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Object Type Confusion
A logic issue was addressed with improved state management
CVE-2022-42824
5.5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
This issue was addressed by removing additional entitlements
CVE-2022-42825
5.5 - Medium
- November 01, 2022
This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-42827
7.8 - High
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Memory Corruption
An issue in code signature validation was addressed with improved checks
CVE-2022-42793
5.5 - Medium
- November 01, 2022
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks.
Improper Input Validation
A memory corruption issue was addressed with improved state management
CVE-2022-42820
7.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app may cause unexpected app termination or arbitrary code execution.
A logic issue was addressed with improved state management
CVE-2022-42817
6.5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. Visiting a maliciously crafted website may leak sensitive data.
A race condition was addressed with improved state handling
CVE-2022-42791
7 - High
- November 01, 2022
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
A certificate validation issue existed in the handling of WKWebView
CVE-2022-42813
9.8 - Critical
- November 01, 2022
A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.
Improper Certificate Validation
An access issue was addressed with additional sandbox restrictions
CVE-2022-42811
5.5 - Medium
- November 01, 2022
An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to access user-sensitive data.
The issue was addressed with improved memory handling
CVE-2022-32899
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32887
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16. An app may be able to execute arbitrary code with kernel privileges.
A logic issue was addressed with improved state management
CVE-2022-32859
5.3 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still appear in spotlight search results.
The issue was addressed with improved memory handling
CVE-2022-32858
5.5 - Medium
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leak sensitive kernel state.
This issue was addressed with improved entitlements
CVE-2022-32835
3.3 - Low
- November 01, 2022
This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to read a persistent device identifier.
A memory corruption issue was addressed with improved state management
CVE-2022-32827
5.5 - Medium
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.
A memory corruption issue was addressed with improved memory handling
CVE-2022-26762
7.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious application may be able to execute arbitrary code with system privileges.
A memory corruption issue was addressed with improved state management
CVE-2022-26719
8.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
This issue was addressed with improved checks
CVE-2022-42800
7.8 - High
- November 01, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A user may be able to cause unexpected app termination or arbitrary code execution.