cbcvebase.
CVE-2022-32917
published 2022-09-20

CVE-2022-32917: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An…

PriorityP183high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-10-05
Exploited in the wild
EPSS
5.56%
92.0th percentile
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < 1616
appleios_15.7_and_ipados
appleipados< 15.715.7
appleiphone_os< 15.715.7
applemacos>= 11.0 < 11.711.7
applemacos>= 12.0.0 < 12.612.6
applemacos>= unspecified < 11.711.7
applemacos>= unspecified < 15.715.7
applemacos>= unspecified < 12.612.6
applemacos_big_sur
applemacos_monterey

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2022-32917 is a kernel out-of-bounds vulnerability exploited via an attacker-controlled application to execute arbitrary code with kernel privileges on Apple platforms (macOS, iOS, iPadOS)
  • CVE-2022-32917 was confirmed actively exploited in the wild at time of patch release; treat any unpatched Apple device (macOS Monterey <12.6, iOS/iPadOS <15.7, macOS Big Sur <11.7) as a high-priority detection target
  • The vulnerability resides in the Kernel component and was fixed via improved bounds checks; focus kernel integrity monitoring and exploit detection on out-of-bounds memory access patterns on affected Apple OS versions
  • CVE-2022-32917 is part of a pattern of Kernel out-of-bounds memory vulnerabilities patched across consecutive Apple security updates (alongside CVE-2022-32894 and CVE-2022-42827); correlate detections across this vulnerability family for signs of targeted kernel exploitation campaigns
  • CVE-2022-32917 is classified as a local privilege escalation kernel issue; detection should focus on processes unexpectedly gaining kernel-level privileges on macOS, iOS 15.x, and iPadOS 15.x
  • ·Affected platforms are macOS Monterey (fixed in 12.6), macOS Big Sur (fixed in 11.7), iOS and iPadOS (fixed in 15.7), and iOS 16; detections should be scoped to devices running versions prior to these fixes
  • ·No specific exploit sample, hash, or network IOC has been publicly disclosed in the available sources; exploitation is confirmed in-the-wild but technical indicators of compromise are not yet publicly available

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.