QID 610404

Date Published: 2022-04-19

QID 610404: Apple iOS 15.4 and iPadOS 15.4 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A memory corruption issue was addressed with improved state management. CVE-2022-22633
A memory corruption issue was addressed with improved validation. CVE-2022-22666
A buffer overflow was addressed with improved bounds checking. CVE-2022-22634
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-22635
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-22636
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. CVE-2022-22652
An issue with app access to camera metadata was addressed with improved logic. CVE-2022-22598
This issue was addressed with improved checks. CVE-2022-22642
This issue was addressed with improved checks. CVE-2022-22643
A use after free issue was addressed with improved memory management. CVE-2022-22667
An out-of-bounds read was addressed with improved input validation. CVE-2022-22611
A memory consumption issue was addressed with improved memory handling. CVE-2022-22612
A use after free issue was addressed with improved memory management. CVE-2022-22641
A logic issue was addressed with improved restrictions. CVE-2022-22653
A memory corruption issue was addressed with improved validation. CVE-2022-22596
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-22613
A use after free issue was addressed with improved memory management. CVE-2022-22614
A logic issue was addressed with improved state management. CVE-2022-22632
A null pointer dereference was addressed with improved validation. CVE-2022-22638
Multiple memory corruption issues existed in libarchive. These issues were addressed with improved input validation. CVE-2022-22622
An access issue was addressed with improved access restrictions. CVE-2022-22670
A logic issue was addressed with improved state management. CVE-2022-22659
This issue was addressed with improved checks. CVE-2022-22618
The issue was addressed with additional permissions checks. CVE-2022-22609
The issue was addressed with improved permissions logic. CVE-2022-22600
A logic issue was addressed with improved state management. CVE-2022-22639
This issue was addressed with improved checks. CVE-2022-22621
An authentication issue was addressed with improved state management. CVE-2022-22671

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Apple advisory HT213182 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213182 iOS URL Logo support.apple.com/en-in/HT213182