CVE-2022-32917
published 2022-09-20CVE-2022-32917: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An…
PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-10-05
Exploited in the wild
EPSS
5.56%
92.0th percentile
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 16 | 16 |
| apple | ios_15.7_and_ipados | — | — |
| apple | ipados | < 15.7 | 15.7 |
| apple | iphone_os | < 15.7 | 15.7 |
| apple | macos | >= 11.0 < 11.7 | 11.7 |
| apple | macos | >= 12.0.0 < 12.6 | 12.6 |
| apple | macos | >= unspecified < 11.7 | 11.7 |
| apple | macos | >= unspecified < 15.7 | 15.7 |
| apple | macos | >= unspecified < 12.6 | 12.6 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-32917 is a kernel out-of-bounds vulnerability exploited via an attacker-controlled application to execute arbitrary code with kernel privileges on Apple platforms (macOS, iOS, iPadOS) ↗
- →CVE-2022-32917 was confirmed actively exploited in the wild at time of patch release; treat any unpatched Apple device (macOS Monterey <12.6, iOS/iPadOS <15.7, macOS Big Sur <11.7) as a high-priority detection target ↗
- →The vulnerability resides in the Kernel component and was fixed via improved bounds checks; focus kernel integrity monitoring and exploit detection on out-of-bounds memory access patterns on affected Apple OS versions ↗
- →CVE-2022-32917 is part of a pattern of Kernel out-of-bounds memory vulnerabilities patched across consecutive Apple security updates (alongside CVE-2022-32894 and CVE-2022-42827); correlate detections across this vulnerability family for signs of targeted kernel exploitation campaigns ↗
- →CVE-2022-32917 is classified as a local privilege escalation kernel issue; detection should focus on processes unexpectedly gaining kernel-level privileges on macOS, iOS 15.x, and iPadOS 15.x ↗
- ·Affected platforms are macOS Monterey (fixed in 12.6), macOS Big Sur (fixed in 11.7), iOS and iPadOS (fixed in 15.7), and iOS 16; detections should be scoped to devices running versions prior to these fixes ↗
- ·No specific exploit sample, hash, or network IOC has been publicly disclosed in the available sources; exploitation is confirmed in-the-wild but technical indicators of compromise are not yet publicly available ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
cisa·2022-09-14·CVSS 7.8
CVE-2022-32917 [HIGH] CWE-20 Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
Vulnerability: Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
Affected: Apple iOS, iPadOS, and macOS
Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://support.apple.com/en-us/HT213445, https://support.apple.com/en-us/HT213444; https://nvd.nist.gov/vuln/detail/CVE-2022-32917
Remediation Due Date: 2022-10-05
Apple
CVE-2022-32917: iOS 15.7 and iPadOS 15.7
vendor_apple·2022-09-12·CVSS 7.8
CVE-2022-32917 [HIGH] CVE-2022-32917: iOS 15.7 and iPadOS 15.7
Apple Security Update: About the security content of iOS 15.7 and iPadOS 15.7
Product: iOS 15.7 and iPadOS
Version: 15.7
CVE: CVE-2022-32917
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-32917: macOS Big Sur 11.7
vendor_apple·2022-09-12·CVSS 7.8
CVE-2022-32917 [HIGH] CVE-2022-32917: macOS Big Sur 11.7
Apple Security Update: About the security content of macOS Big Sur 11.7
Product: macOS Big Sur
Version: 11.7
CVE: CVE-2022-32917
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-32917: iOS 16
vendor_apple·2022-09-12·CVSS 7.8
CVE-2022-32917 [HIGH] CVE-2022-32917: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-32917
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges.
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-32917: macOS Monterey 12.6
vendor_apple·2022-09-12·CVSS 7.8
CVE-2022-32917 [HIGH] CVE-2022-32917: macOS Monterey 12.6
Apple Security Update: About the security content of macOS Monterey 12.6
Product: macOS Monterey
Version: 12.6
CVE: CVE-2022-32917
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved bounds checks.
VulDB
Apple iOS/iPadOS up to 15.6.1 Kernel out-of-bounds write (HT213445 / EUVD-2022-35983)
vuldb·2026-06-06·CVSS 7.8
CVE-2022-32917 [HIGH] Apple iOS/iPadOS up to 15.6.1 Kernel out-of-bounds write (HT213445 / EUVD-2022-35983)
A vulnerability classified as critical was found in Apple iOS and iPadOS up to 15.6.1. Impacted is an unknown function of the component Kernel. The manipulation results in out-of-bounds write.
This vulnerability was named CVE-2022-32917. The attack needs to be approached locally. In addition, an exploit is available.
Upgrading the affected component is advised.
VulDB
Apple macOS up to 12.5.1 Kernel buffer overflow (HT213444 / EUVD-2022-35983)
vuldb·2026-06-06·CVSS 7.8
CVE-2022-32917 [HIGH] Apple macOS up to 12.5.1 Kernel buffer overflow (HT213444 / EUVD-2022-35983)
A vulnerability described as critical has been identified in Apple macOS up to 12.5.1. The affected element is an unknown function of the component Kernel. The manipulation results in buffer overflow.
This vulnerability is known as CVE-2022-32917. Attacking locally is a requirement. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-fffx-3h8f-f943: The issue was addressed with improved bounds checks
ghsa_unreviewed·2022-09-21
CVE-2022-32917 [HIGH] CWE-787 GHSA-fffx-3h8f-f943: The issue was addressed with improved bounds checks
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-32917 [HIGH] CWE-20 Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges.
Affected: Apple iOS, iPadOS, and macOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/kb/HT213443; https://support.apple.com/kb/HT213444; https://support.apple.com/kb/HT213445; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Report_2022.pdf
Remediation Due: 2022-10-05
Project0
Project Zero RCA: CVE-2022-32917: AppleSPU out of bounds write
project_zero·CVSS 7.8
CVE-2022-32917 [HIGH] Project Zero RCA: CVE-2022-32917: AppleSPU out of bounds write
# CVE-2022-32917: AppleSPU out of bounds write
*Ned Williamson*
## The Basics
**Disclosure or Patch Date:** 2022 September 12
**Product:** Apple iOS, macOS
**Advisory:**
*iOS:* https://support.apple.com/en-us/HT213445
*macOS:* https://support.apple.com/en-us/HT213443
**Affected Versions:** iOS 15.7, macOS 11.7 and earlier
**First Patched Version:** iOS 15.7, macOS 11.7
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:** This can be triggered by creating an `IOUserClient` to send messages to the `_asyncMessage` object. This can be done by its exposed `RTBuddy` interface.
**Exploit sample:** N/A
**Did you have access to the exploit sample when doing the analysis?** No
## The Vulnerability
**Bug
No detection rules found.
No public exploits indexed.
Talos
Threat Source newsletter (Oct. 27, 2022): I thought we were already aware of supply chain attacks?
blogs_talos·2022-10-27
Threat Source newsletter (Oct. 27, 2022): I thought we were already aware of supply chain attacks?
## Threat Source newsletter (Oct. 27, 2022): I thought we were already aware of supply chain attacks?
Welcome to this week’s edition of the Threat Source newsletter.
There are plenty of jokes about whether we’re “aware” of cybersecurity during National Cybersecurity Awareness Month. But now I’m wondering if people are aware of supply chain attacks.
I thought we hit the pinnacle of supply chain attacks in 2020 with the SolarWinds attack , when these types of attacks dominated headlines and defenders started shouting from the mountaintops about how important it is to be ready for supply chain attacks.
And then Kaseya came along a few months later when attackers found a different way to deploy malicious updates that were disguised as legitimate patches.
And still today, we’re warning abo
Talos
Threat Source newsletter (Oct. 27, 2022): I thought we were already aware of supply chain attacks?
blogs_talos·2022-10-27
Threat Source newsletter (Oct. 27, 2022): I thought we were already aware of supply chain attacks?
Welcome to this week’s edition of the Threat Source newsletter.
There are plenty of jokes about whether we’re “aware” of cybersecurity during National Cybersecurity Awareness Month. But now I’m wondering if people are aware of supply chain attacks.
I thought we hit the pinnacle of supply chain attacks in 2020 with the SolarWinds attack, when these types of attacks dominated headlines and defenders started shouting from the mountaintops about how important it is to be ready for supply chain attacks.
And then Kaseya came along a few months later when attackers found a different way to deploy malicious updates that were disguised as legitimate patches.
And still today, we’re warning about the dangers of how prevalent supply chain attacks are and how everyone needs to be ready for this att
Checkpoint
19th September – Threat Intelligence Report
blogs_checkpoint·2022-09-19
CVE-2022-29499 19th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 19th September, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Uber has suffered a data breach, allegedly by an 18-year-old hacker who managed to gain access using social engineering tactics on an employee. The hacker claims to have access to Uber’s internal IT systems and to the company’s HackerOne bug bounty account, which contains vulnerabilities in Uber’s systems and apps, di
Talos
Threat Source newsletter (Sept. 15, 2022) — Teachers have to be IT admins now, too
blogs_talos·2022-09-15
Threat Source newsletter (Sept. 15, 2022) — Teachers have to be IT admins now, too
## Threat Source newsletter (Sept. 15, 2022) — Teachers have to be IT admins now, too
Welcome to this week’s edition of the Threat Source newsletter. Public schools in the United States already rely on our teachers for so much — they have to be educators, occasional parental figures, nurses, safety officers, law enforcement and much more. Slowly, they’re having to add “IT admin” to their list of roles. Educational institutions have increasingly become a target for ransomware attacks, an issue already highlighted this year by a major cyber attack on the combined Los Angeles school district in California that schools are still recovering from. Teachers there reported that during the week of the attack, they couldn’t enter attendance, lost lesson plans and presentations, and had to scrap hom
Talos
Threat Source newsletter (Sept. 15, 2022) — Teachers have to be IT admins now, too
blogs_talos·2022-09-15
Threat Source newsletter (Sept. 15, 2022) — Teachers have to be IT admins now, too
Welcome to this week’s edition of the Threat Source newsletter.
Public schools in the United States already rely on our teachers for so much — they have to be educators, occasional parental figures, nurses, safety officers, law enforcement and much more. Slowly, they’re having to add “IT admin” to their list of roles.
Educational institutions have increasingly become a target for ransomware attacks, an issue already highlighted this year by a major cyber attack on the combined Los Angeles school district in California that schools are still recovering from.
Teachers there reported that during the week of the attack, they couldn’t enter attendance, lost lesson plans and presentations, and had to scrap homework plans. Technology has become ever-present in classrooms, so any minimal disrup
http://seclists.org/fulldisclosure/2022/Oct/39http://seclists.org/fulldisclosure/2022/Oct/40http://seclists.org/fulldisclosure/2022/Oct/43http://seclists.org/fulldisclosure/2022/Oct/45https://support.apple.com/en-us/HT213443https://support.apple.com/en-us/HT213444https://support.apple.com/en-us/HT213445https://support.apple.com/en-us/HT213446http://seclists.org/fulldisclosure/2022/Oct/39http://seclists.org/fulldisclosure/2022/Oct/40http://seclists.org/fulldisclosure/2022/Oct/43http://seclists.org/fulldisclosure/2022/Oct/45https://support.apple.com/en-us/HT213443https://support.apple.com/en-us/HT213444https://support.apple.com/en-us/HT213445https://support.apple.com/en-us/HT213446https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-32917
2022-09-20
Published
2022-09-14
Added to CISA KEV
Exploited in the wild