QID 610395

Date Published: 2022-01-27

QID 610395: Apple iOS 15.3 and iPadOS 15.3 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A memory corruption issue was addressed with improved validation. CVE-2022-22584
A logic issue was addressed with improved validation. CVE-2022-22578
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. CVE-2022-22585
A memory corruption issue was addressed with improved input validation. CVE-2022-22587
A buffer overflow issue was addressed with improved memory handling. CVE-2022-22593
An information disclosure issue was addressed with improved state management. CVE-2022-22579
A validation issue was addressed with improved input sanitization. CVE-2022-22589
A use after free issue was addressed with improved memory management. CVE-2022-22590
A logic issue was addressed with improved state management. CVE-2022-22592
A cross-origin issue in the IndexDB API was addressed with improved input validation. CVE-2022-22594

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213053 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213053 iOS URL Logo support.apple.com/en-in/HT213053