QID 610440

Date Published: 2022-11-01

QID 610440: Apple iOS 15.7.1 and iPadOS 15.7.1 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
The issue was addressed with improved memory handling. CVE-2022-32932
The issue was addressed with improved memory handling. CVE-2022-42798
A permissions issue was addressed with additional restrictions. CVE-2022-32929
A lock screen issue was addressed with improved state management. CVE-2022-32935
The issue was addressed with improved bounds checks. CVE-2022-32939
This issue was addressed with improved checks. CVE-2022-32949
A memory corruption issue was addressed with improved state management. CVE-2022-32944
A race condition was addressed with improved locking. CVE-2022-42803
The issue was addressed with improved bounds checks. CVE-2022-32926
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-42827
A logic issue was addressed with improved checks. CVE-2022-42801
The issue was addressed with improved memory handling. CVE-2022-42810
The issue was addressed with improved bounds checks. CVE-2022-32941
A logic issue was addressed with improved state management. CVE-2022-42817
A correctness issue in the JIT was addressed with improved checks. WebKit Bugzilla
The issue was addressed with improved memory handling. CVE-2022-32927
This issue was addressed with improved checks. CVE-2022-37434

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213490 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213490 iOS URL Logo support.apple.com/en-in/HT213490