LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-32917: Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 14, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-32917 to its Known Exploited Vulnerabilities catalog on Sep 14, 2022, with a federal patch deadline of Oct 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges.

CVE-2022-32917 is a vulnerability in the Apple kernel that ships with iOS, iPadOS, and macOS. An application may be able to execute code with kernel privileges, giving it the highest level of control over the device. For IT and security teams this matters because kernel-level code execution can bypass most user-space protections, enable persistence, and allow further compromise of data or the wider environment.

Public detail on the exact trigger is limited; defenders should treat any untrusted or malicious application as a potential vector and confirm all technical specifics against the current Apple security advisory.

How it works

The issue is classified under CWE-20 (Improper Input Validation) and CWE-787 (Out-of-bounds Write). In broad terms for this class of kernel flaws, the kernel fails to properly validate or bound-check data supplied by an application. An attacker who can run code in user space—typically via a malicious or compromised app—can supply crafted input that causes the kernel to write outside intended memory bounds or process invalid data. Successful abuse elevates the attacker’s code to kernel privileges, allowing arbitrary operations at the most privileged level of the operating system.

No public exploit mechanics or proof-of-concept details are provided in the available record; any deeper analysis must be validated against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

The vulnerability affects Apple devices running iOS, iPadOS, or macOS that include the vulnerable kernel. These platforms are common on employee smartphones, tablets, and laptops, as well as in BYOD and managed fleets.

Because the vulnerability resides in the kernel itself, any device that has not yet received the vendor update should be treated as in-scope until confirmed otherwise.

How to remediate

The primary remediation is to apply the security updates released by Apple. Follow the vendor instructions exactly: install the latest available iOS, iPadOS, or macOS release that addresses CVE-2022-32917 through official channels (Settings updates, Software Update, or managed deployment).

CISA’s required action is simply to apply updates per vendor instructions; no additional vendor-specific workarounds are documented in the available facts.

If you can't patch immediately

When immediate patching is blocked by testing, operational, or compatibility constraints, apply compensating controls to reduce the attack surface until the update can be installed.

These measures lower risk but do not eliminate it; schedule the official update as soon as feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this severity can lead to full device compromise and subsequent data breaches. If you suspect an affected device was targeted before patching, treat any credentials, tokens, or files accessible from that device as potentially exposed. Rotate secrets, review access logs, and consider a full forensic examination of the device. Readers can also run a free exposure scan of their email addresses against known breach data sets to determine whether personal or corporate accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS, iPadOS, and macOS
WeaknessCWE-20
Added to CISA KEVSep 14, 2022
Federal patch deadlineOct 5, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities