LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-32894: Apple iOS and macOS Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 8, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-32894 to its Known Exploited Vulnerabilities catalog on Aug 18, 2022, with a federal patch deadline of Sep 8, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.

CVE-2022-32894 is an out-of-bounds write vulnerability in Apple iOS and macOS that can allow an application to execute code with kernel privileges. For IT and security teams, this matters because kernel-level code execution can undermine device integrity, persistence controls, and isolation between apps and the operating system. Public detail is limited to the CISA summary and the stated weakness classes; confirm exact scope, fixed builds, and any platform-specific notes against the vendor advisory.

CISA’s required action is to apply updates per vendor instructions. Known ransomware use is not documented for this CVE.

How it works

This issue is classified under CWE-787 (out-of-bounds write) and CWE-20 (improper input validation). In plain terms, a component fails to keep a write operation inside the memory bounds it should use. When bounds and input checks are insufficient, a malicious or compromised application can corrupt memory that the kernel relies on.

Abuse follows the usual pattern for this class: an application supplies crafted input or triggers a code path that causes a write past the end (or before the start) of an intended buffer. Successful corruption can alter control data or other kernel state, which in turn can lead to execution with kernel privileges. Exact exploit mechanics, trigger surfaces, and reliability are not provided in the given facts; treat any public proof-of-concept claims cautiously and validate behavior only against Apple’s advisory and your own lab testing on authorized systems.

Am I affected? How to find it in your systems

The vulnerability affects Apple iOS and macOS. These platforms typically appear as employee iPhones and iPads, Mac laptops and desktops, and any managed or BYOD devices enrolled in MDM.

How to remediate

Patch first. Apply the updates Apple released for this issue, following the vendor instructions referenced by CISA. Use MDM to enforce minimum OS versions and to drive supervised devices to the fixed builds as quickly as testing allows.

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until the vendor update is installed.

If your data may have been exposed

Actively exploited vulnerabilities that yield kernel privileges can lead to device compromise and follow-on access to accounts, tokens, or files available to that device. If you suspect exposure, isolate affected devices, rotate credentials and tokens used on them, and review access logs for mail, VPN, and cloud apps. You can run a free exposure scan of your email to check known breach data and determine whether addresses tied to your environment already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS and macOS
WeaknessCWE-20
Added to CISA KEVAug 18, 2022
Federal patch deadlineSep 8, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities