QID 610416

Date Published: 2022-05-19

QID 610416: Apple iOS 15.5 and iPadOS 15.5 Security Update Missing (HT213258)

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A use after free issue was addressed with improved memory management. CVE-2022-26702
A memory corruption issue was addressed with improved input validation. CVE-2022-26751
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-26736
An out-of-bounds access issue was addressed with improved bounds checking. CVE-2022-26763
A memory corruption issue was addressed with improved state management. CVE-2022-26744
An integer overflow issue was addressed with improved input validation. CVE-2022-26711
A race condition was addressed with improved locking. CVE-2022-26701
A memory corruption issue was addressed with improved state management. CVE-2022-26768
A memory corruption issue was addressed with improved state management. CVE-2022-26771
A memory corruption issue was addressed with improved validation. CVE-2022-26714
A use after free issue was addressed with improved memory management. CVE-2022-26757
A memory corruption issue was addressed with improved validation. CVE-2022-26764
A race condition was addressed with improved state handling. CVE-2022-26765
An access issue was addressed with additional sandbox restrictions on third-party applications. CVE-2022-26706
A use after free issue was addressed with improved memory management. CVE-2022-23308 Notes Available for
This issue was addressed with improved checks. CVE-2022-22673
A logic issue was addressed with improved state management. CVE-2022-26731
A certificate parsing issue was addressed with improved checks. CVE-2022-26766
An authorization issue was addressed with improved state management. CVE-2022-26703
A memory corruption issue was addressed with improved state management. WebKit Bugzilla
A use after free issue was addressed with improved memory management. WebKit Bugzilla
A memory corruption issue was addressed with improved state management. WebKit Bugzilla
A logic issue in the handling of concurrent media was addressed with improved state handling. WebKit Bugzilla
A memory corruption issue was addressed with improved validation. CVE-2022-26745
A memory corruption issue was addressed with improved state management. CVE-2022-26760
This issue was addressed with improved checks. CVE-2015-4142
A memory corruption issue was addressed with improved memory handling. CVE-2022-26762

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Apple advisory HT213258 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213258 iOS URL Logo support.apple.com/en-in/HT213258