First published: Wed Jul 20 2022(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Credit: Mohamed Ghannam @_simo36 Mohamed Ghannam @_simo36 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <15.6 | 15.6 |
Apple iPadOS | <15.6 | 15.6 |
Apple iPadOS | <15.6 | |
Apple iPhone OS | <15.6 | |
Apple macOS | >=12.0.0<12.5 | |
<12.5 | 12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-32948 is a vulnerability in Apple Neural Engine that allows an out-of-bounds read.
The severity of CVE-2022-32948 depends on the specific circumstances.
CVE-2022-32948 can be exploited by an attacker who has local access to the affected device.
To fix CVE-2022-32948, update your Apple software to the latest version available.
You can find more information about CVE-2022-32948 on the official Apple support page: [CVE-2022-32948](https://support.apple.com/en-us/HT213345)