Skip to main content

Apple Releases Security Updates for Multiple Products

The security updates include an exploited vulnerability in iOS, iPadOS, Safari, tvOS, and macOS Ventura

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The security updates include an exploited vulnerability in iOS, iPadOS, Safari, tvOS, and macOS Ventura


Threat details

Introduction

Apple has released nine security updates to address vulnerabilities in multiple products. Apple is reporting exploitation of CVE-2022-42856, which impacts iOS, iPadOS, Safari, tvOS, and macOS Ventura. A remote attacker could exploit some of these vulnerabilities to take control of a vulnerable system.

Exploitation and Proof-of-Concept reported for multiple vulnerabilities

Apple has released a new security update to resolve an exploited vulnerability tracked as CVE-2022-42856 and within iOS, iPadOS, Safari, tvOS, and macOS Ventura. The vulnerability could allow an attacker to execute arbitrary code on the device after processing maliciously crafted web content. This vulnerability could enable an attacker to execute malicious code on the device or to corrupt sensitive data.

Microsoft Security Vulnerability Research team has released a proof-of-concept for CVE-2022-42821 which they have called "Achilles". The vulnerability could allow attackers to bypass application execution restrictions imposed by Apple’s Gatekeeper security mechanism, designed to ensure only trusted apps run on Mac devices.

A proof-of-concept has been released for CVE-2022-46689 and there have been reports of active exploitation in the wild. CVE-2022-46689 a race condition vulnerability that could allow a malicious app to execute arbitrary code with kernel privileges. 

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2022-48168 to their Known Exploited Vulnerability Catalog based on evidence of active exploitation in the wild.


Threat updates

Date Update
1 Feb 2024 Active exploitation of CVE-2022-48618

This article has been updated to reflect this change in the status of exploitation. 

10 Feb 2023 Exploitation and Proof-of-Concept reported for CVE-2022-46689

This article has been updated to reflect this change in the status of exploitation. 

20 Dec 2022 Microsoft Releases Proof-of-Concept for CVE-2022-42821

Microsoft Security Vulnerability Research team has released a proof-of-concept for CVE-2022-42821 which they have called "Achilles". This article has been updated to reflect those changes. 


Remediation advice

Affected organisations are encouraged to review the following Apple security advisories and apply any relevant updates or workarounds.


Remediation steps

Type Step
Patch

iCloud for Windows 14.1 | HT213538


https://support.apple.com/en-us/HT213538
Patch

Safari 16.2 | HT213537


https://support.apple.com/en-us/HT213537
Patch

macOS Monterey 12.6.2 | HT213533


https://support.apple.com/en-us/HT213533
Patch

macOS Big Sur 11.7.2 | HT213534


https://support.apple.com/en-us/HT213534
Patch

tvOS 16.2 | HT213535


https://support.apple.com/en-us/HT213535
Patch

watchOS 9.2 | HT213536 


https://support.apple.com/en-us/HT213536
Patch

iOS 15.7.2 and iPadOS 15.7.2 | HT213531


https://support.apple.com/en-us/HT213531
Patch

iOS 16.2 and iPadOS 16.2 | HT213530


https://support.apple.com/en-us/HT213530
Patch

macOS Ventura 13.1 | HT213532


https://support.apple.com/en-us/HT213532

Definitive source of threat updates


CVE Vulnerabilities

Last edited: 1 February 2024 1:29 pm