IOMobileFrameBuffer. A memory corruption issue was addressed with improved input validation.
HomeKit. A state issue existed in the handling of Home Control. This issue was addressed through improved validation.
Accessibility. A logging issue was addressed with improved data redaction.
Accessibility. A logging issue was addressed with improved data redaction.
Accessibility. A logging issue was addressed with improved data redaction.
Accessibility. The issue was addressed with improved authentication.
Accessibility. The issue was addressed with improved authentication.
Accessibility. The issue was addressed with improved authentication.
Apple Neural Engine. The issue was addressed with improved memory handling.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.
Apple Neural Engine. The issue was addressed with improved memory handling.
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. This issue was addressed by restricting options offered on a locked device.
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
A flaw was found in WebKitGTK. A type confusion issue was addressed with improved memory handling.
Reference: https://webkitgtk.org/security/WSA-2022-0001.html
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, tvOS 17, macOS Sonoma 14, Safari 17. Processing web content may lead to arbitrary code execution.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution.
IOSurfaceAccelerator. A memory corruption issue was addressed with improved state management.
AMD. A memory corruption issue was addressed with improved input validation.
A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.
AMD. A memory corruption issue was addressed with improved input validation.