Apple Security Advisories · September 2022 — Apple Security Advisories
29 advisories 29 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2022-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-32917

iPadOSExploitedCISA KEV listedCRITICAL2022-09-12

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a repo...

CVEs:CVE-2022-32917

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2022-32833

iOSActive exploitation (sightings)MEDIUM2022-09-12

An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.

CVEs:CVE-2022-32833

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2022-32887

iOSActive exploitation (sightings)CRITICAL2022-09-12

The issue was addressed with improved memory handling. This issue is fixed in iOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2022-32887

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2022-32916

iOSActive exploitation (sightings)MEDIUM2022-09-12

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 16. An app may be able to disclose kernel memory.

CVEs:CVE-2022-32916

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2022-32886

iPadOSPoC exploitCRITICAL2022-09-12

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2022-32886

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2022-32912

iPadOSPoC exploitCRITICAL2022-09-12

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2022-32912

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2022-46709

macOSPoC exploitCRITICAL2022-09-12

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges

CVEs:CVE-2022-46709

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2022-32883

iPadOSPoC exploitMEDIUM2022-09-12

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.

CVEs:CVE-2022-32883

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2022-32911

iPadOSPoC exploitCRITICAL2022-09-12

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2022-32911

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-32908

iPadOSPoC exploitCRITICAL2022-09-12

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.

CVEs:CVE-2022-32908

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-32864

iPadOSPoC exploitMEDIUM2022-09-12

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to disclose kernel memory.

CVEs:CVE-2022-32864

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-26707

macOSPoC exploitMEDIUM2022-09-23

An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS Monterey 12.4. A user may be able to view sensitive user information.

CVEs:CVE-2022-26707

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32889

watchOSPoC exploitCRITICAL2022-09-12

The issue was addressed with improved memory handling. This issue is fixed in iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2022-32889

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2022-32782

macOSPoC exploitMEDIUM2022-09-23

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVEs:CVE-2022-32782

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32902

macOSPoC exploitMEDIUM2022-09-13

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.

CVEs:CVE-2022-32902

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32783

macOSPoC exploitMEDIUM2022-09-23

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An app may gain unauthorized access to Bluetooth.

CVEs:CVE-2022-32783

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32900

macOSPoC exploitHIGH2022-09-13

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to gain elevated privileges.

CVEs:CVE-2022-32900

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32896

macOSPoC exploitMEDIUM2022-09-13

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. A user may be able to view sensitive user information.

CVEs:CVE-2022-32896

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-32868

iPadOSCoalition ESS < 30%MEDIUM2022-09-12

A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.

CVEs:CVE-2022-32868

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2022-3252

OtherCoalition ESS < 30%HIGH2022-09-21

Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These two objects (HTTPRequestDecompressor and HTTPResponseDecompressor) both fa...

CVEs:CVE-2022-3252

Affected products

ProductStatusVendorPackageEcosystem
swift-nio-extras affected apple
Upstream advisory

CVE-2022-32891

watchOSCoalition ESS < 30%MEDIUM2022-09-13

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.

CVEs:CVE-2022-32891

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-32795

iPadOSCoalition ESS < 30%MEDIUM2022-09-12

This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2022-32795

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2022-3215

OtherCoalition ESS < 30%CRITICAL2022-09-28

NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server accepts user generated input from an incoming request and reflects it into a HTTP/1.1 response header in...

CVEs:CVE-2022-3215

Affected products

ProductStatusVendorPackageEcosystem
swiftnio affected apple
Upstream advisory

CVE-2022-37724

OtherCoalition ESS < 30%CRITICAL2022-09-14

Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.

CVEs:CVE-2022-37724

Affected products

ProductStatusVendorPackageEcosystem
webobjects affected apple
Upstream advisory

CVE-2022-32872

iPadOSCoalition ESS < 30%LOW2022-09-12

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.

CVEs:CVE-2022-32872

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2022-32854

iPadOSCoalition ESS < 30%MEDIUM2022-09-12

This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.

CVEs:CVE-2022-32854

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2022-32871

iOSCoalition ESS < 30%LOW2022-09-12

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with physical access to a device may be able to use Siri to access private calendar information

CVEs:CVE-2022-32871

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2022-32925

watchOSCoalition ESS < 30%CRITICAL2022-09-12

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2022-32925

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-36521

iPadOSEPSS <= 49%HIGH2022-09-23

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted ...

CVEs:CVE-2020-36521

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.