Apple Releases Security Updates for Multiple Products
The security updates include an exploited vulnerability in iOS, iPadOS, Safari, tvOS, and macOS Ventura
Summary
The security updates include an exploited vulnerability in iOS, iPadOS, Safari, tvOS, and macOS Ventura
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Apple has released nine security updates to address vulnerabilities in multiple products. Apple is reporting exploitation of CVE-2022-42856, which impacts iOS, iPadOS, Safari, tvOS, and macOS Ventura. A remote attacker could exploit some of these vulnerabilities to take control of a vulnerable system.
Exploitation and Proof-of-Concept reported for multiple vulnerabilities
Apple has released a new security update to resolve an exploited vulnerability tracked as CVE-2022-42856 and within iOS, iPadOS, Safari, tvOS, and macOS Ventura. The vulnerability could allow an attacker to execute arbitrary code on the device after processing maliciously crafted web content. This vulnerability could enable an attacker to execute malicious code on the device or to corrupt sensitive data.
Microsoft Security Vulnerability Research team has released a proof-of-concept for CVE-2022-42821 which they have called "Achilles". The vulnerability could allow attackers to bypass application execution restrictions imposed by Appleās Gatekeeper security mechanism, designed to ensure only trusted apps run on Mac devices.
A proof-of-concept has been released for CVE-2022-46689 and there have been reports of active exploitation in the wild. CVE-2022-46689 a race condition vulnerability that could allow a malicious app to execute arbitrary code with kernel privileges.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2022-48168 to their Known Exploited Vulnerability Catalog based on evidence of active exploitation in the wild.
Threat updates
| Date | Update |
|---|---|
| 1 Feb 2024 |
Active exploitation of CVE-2022-48618
This article has been updated to reflect this change in the status of exploitation. |
| 10 Feb 2023 |
Exploitation and Proof-of-Concept reported for CVE-2022-46689
This article has been updated to reflect this change in the status of exploitation. |
| 20 Dec 2022 |
Microsoft Releases Proof-of-Concept for CVE-2022-42821
Microsoft Security Vulnerability Research team has released a proof-of-concept for CVE-2022-42821 which they have called "Achilles". This article has been updated to reflect those changes. |
Remediation advice
Affected organisations are encouraged to review the following Apple security advisories and apply any relevant updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
iCloud for Windows 14.1 | HT213538 https://support.apple.com/en-us/HT213538 |
| Patch |
Safari 16.2 | HT213537 https://support.apple.com/en-us/HT213537 |
| Patch |
macOS Monterey 12.6.2 | HT213533 https://support.apple.com/en-us/HT213533 |
| Patch |
macOS Big Sur 11.7.2 | HT213534 https://support.apple.com/en-us/HT213534 |
| Patch |
tvOS 16.2 | HT213535 https://support.apple.com/en-us/HT213535 |
| Patch |
watchOS 9.2 | HT213536 https://support.apple.com/en-us/HT213536 |
| Patch |
iOS 15.7.2 and iPadOS 15.7.2 | HT213531 https://support.apple.com/en-us/HT213531 |
| Patch |
iOS 16.2 and iPadOS 16.2 | HT213530 https://support.apple.com/en-us/HT213530 |
| Patch |
macOS Ventura 13.1 | HT213532 https://support.apple.com/en-us/HT213532 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 1 February 2024 1:29 pm