10
CVSSv3

CVE-2022-32845

Published: 23/09/2022 Updated: 09/01/2023
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple macos

apple iphone os

apple ipados

apple watchos

Vendor Advisories

About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...

Github Repositories

ANE kernel r/w exploit for iOS 15 and macOS 12

WeightBufs: WeightBufs is a kernel r/w exploit for all Apple devices with Neural Engine support Bugs and Exploit by @simo36, you can read my presentation slides at POC for more details about the vulnerabilities and the exploitation techniques The exploit doesn't rely on any hardcoded address or offset, and it should work AS IS on macOS12 up to 124 and *OS 15 up to 155

CVE-2022-32898 CVE-2022-32898: ANE_ProgramCreate() multiple kernel memory corruption Nov 23, 2022 • Mohamed GHANNAM (@_simo36) Intro: While reverse-engineering the process of which the Apple Neural Engine loads a model in the kernel level, I identified two interesting memory corruption vulnerabilities in the code responsible for processing the neural network features in H1

WeightBufs: WeightBufs is a kernel r/w exploit for all Apple devices with Neural Engine support Bugs and Exploit by @simo36, you can read my presentation slides at POC for more details about the vulnerabilities and the exploitation techniques The exploit doesn't rely on any hardcoded address or offset, and it should work AS IS on macOS12 up to 124 and *OS 15 up to 155