QID 610425

Date Published: 2022-07-27

QID 610425: Apple iOS 15.6 and iPadOS 15.6 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
The issue was addressed with improved memory handling. CVE-2022-32832
A buffer overflow was addressed with improved bounds checking. CVE-2022-32788
The issue was addressed with improved memory handling. CVE-2022-32824
An authorization issue was addressed with improved state management. CVE-2022-32826
This issue was addressed with improved checks. CVE-2022-32845
This issue was addressed with improved checks. CVE-2022-32840
The issue was addressed with improved memory handling. CVE-2022-32810
An out-of-bounds write issue was addressed with improved input validation. CVE-2022-32820
The issue was addressed with improved memory handling. CVE-2022-32825
The issue was addressed with improved memory handling. CVE-2022-32828
The issue was addressed with improved bounds checks. CVE-2022-32839
A logic issue was addressed with improved state management. CVE-2022-32819
Multiple out-of-bounds write issues were addressed with improved bounds checking. CVE-2022-32793
A memory corruption issue was addressed with improved validation. CVE-2022-32821
A logic issue was addressed with improved state management. CVE-2022-32855
An information disclosure issue was addressed by removing the vulnerable code. CVE-2022-32849
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-32787
The issue was addressed with improved memory handling. CVE-2022-32841
A logic issue was addressed with improved checks. CVE-2022-32802
An out-of-bounds read issue was addressed with improved bounds checking. CVE-2022-32830
A null pointer dereference was addressed with improved validation. CVE-2022-32785
A memory corruption issue was addressed with improved state management. CVE-2022-26768
The issue was addressed with improved memory handling. CVE-2022-32813
An out-of-bounds read issue was addressed with improved bounds checking. CVE-2022-32817
A logic issue was addressed with improved state management. CVE-2022-32844
A race condition was addressed with improved state handling. CVE-2022-32844
This issue was addressed with improved checks. CVE-2022-26981
A memory initialization issue was addressed with improved memory handling. CVE-2022-32823 Multi-Touch Available for
A type confusion issue was addressed with improved state handling. CVE-2022-32814
A logic issue was addressed with improved state management. CVE-2022-32838
The issue was addressed with improved UI handling. CVE-2022-32784
This issue was addressed by using HTTPS when sending information over the network. CVE-2022-32857
The issue was addressed with improved UI handling. WebKit Bugzilla
An out-of-bounds write issue was addressed with improved input validation. WebKit Bugzilla
A memory corruption issue was addressed with improved state management. WebKit Bugzilla

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Apple advisory HT213346 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213346 iOS URL Logo support.apple.com/en-in/HT213346