Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
Apple iOS, iPadOS, and macOS Memory Corruption Vulnerability Allowing Arbitrary Code Execution with Kernel Privileges
Vulnerability
A memory corruption vulnerability has been identified in the IOMobileFrameBuffer component of Apple iOS, iPadOS, and macOS. This vulnerability allows a malicious application to execute arbitrary code with kernel privileges. It affects iOS 15.3, iPadOS 15.3, macOS Big Sur 11.6.3, and macOS Monterey 12.2. The issue has been addressed with improved input validation, but Apple is aware of reports suggesting that this vulnerability may have been actively exploited.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution with kernel privileges, allowing a malicious application to gain elevated rights and potentially manipulate system-level functions or access sensitive information.
Remediation
Users can update to iOS 15.3, iPadOS 15.3, macOS Big Sur 11.6.3, or macOS Monterey 12.2 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
