QID 610393

Date Published: 2022-01-27

QID 610393: Apple iOS 15.2 and iPadOS 15.2 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30960
A logic issue was addressed with improved state management. CVE-2021-30966
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30957
An out-of-bounds read was addressed with improved input validation. CVE-2021-30958
This issue was addressed with improved checks. CVE-2021-30945
This issue was addressed with improved handling of file metadata. CVE-2021-30992
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30939
A race condition was addressed with improved state handling. CVE-2021-30996
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30983
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2021-30985
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30991
A memory corruption vulnerability was addressed with improved locking. CVE-2021-30937
A use after free issue was addressed with improved memory management. CVE-2021-30927
A memory corruption issue was addressed with improved state management. CVE-2021-30949
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30993
A race condition was addressed with improved state handling. CVE-2021-30955
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2021-30971
An out-of-bounds read was addressed with improved input validation. CVE-2021-30973
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2021-30929
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30979
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30940
The issue was addressed with improved permissions logic. CVE-2021-30932
An inconsistent user interface issue was addressed with improved state management. CVE-2021-30948
A race condition was addressed with improved state handling. CVE-2021-30995
A validation issue related to hard link behavior was addressed with improved sandbox restrictions. CVE-2021-30968
A logic issue was addressed with improved restrictions. CVE-2021-30946
An access issue was addressed with additional sandbox restrictions. CVE-2021-30947
A logic issue was addressed with improved state management. CVE-2021-30767
An inherited permissions issue was addressed with additional restrictions. CVE-2021-30964
A buffer overflow issue was addressed with improved memory handling. CVE-2021-30934
A use after free issue was addressed with improved memory management. CVE-2021-30936
An integer overflow was addressed with improved input validation. CVE-2021-30952
A race condition was addressed with improved state handling. CVE-2021-30984
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30953
A type confusion issue was addressed with improved memory handling. CVE-2021-30954

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Apple advisory HT212976 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212976 iOS URL Logo support.apple.com/en-in/HT212976