Apple Release Security Updates on Multiple Products
Scheduled updates for Apple products
Summary
Scheduled updates for Apple products
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Apple has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.
A zero-day vulnerability, tracked as CVE-2022-2294, is a memory corruption issue in Safari. An attacker could exploit this vulnerability using maliciously crafted web content to obtain arbitrary code execution.
Proof-of-Concept for vulnerabilities in iOS, iPadOS, and macOS released
A proof-of-concept (PoC) is now available for remote code execution (RCE) vulnerabilities known as CVE-2022-32845, CVE-2022-32948, CVE-2022-42805, CVE-2022-32899.
Threat updates
| Date | Update |
|---|---|
| 17 Nov 2022 |
Proof-of-Concept Released
This Cyber Alert is updated to reflect the release of a PoC involving multiple vulnerabilities. |
Remediation advice
Affected organisations are encouraged to review the Apple security advisories and apply the following relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Safari 15.6 https://support.apple.com/kb/HT213341 |
| Patch |
tvOS 15.6 https://support.apple.com/kb/HT213342 |
| Patch |
macOS Catalina Security Update 2022-005 https://support.apple.com/kb/HT213343 |
| Patch |
macOS Big Sur 11.6.8 https://support.apple.com/kb/HT213344 |
| Patch |
macOS Monterey 12.5 https://support.apple.com/kb/HT213345 |
| Patch |
iOS 15.6 and iPadOS 15.6 https://support.apple.com/kb/HT213346 |
| Patch |
watchOS 8.7 https://support.apple.com/kb/HT213340 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 17 November 2022 3:01 pm