Vulnerability record · CVE-2022-32917 · published 20 September 2022
CVE-2022-32917: Apple iOS, iPadOS and macOS out-of-bounds write in kernel
Apple · Ipados
An out-of-bounds write (CWE-787) in Apple's kernel was addressed with improved bounds checks in macOS Monterey 12.6, macOS Big Sur 11.7, iOS 15.7/iPadOS 15.7 and iOS 16. A local application can trigger the flaw to execute arbitrary code with kernel privileges, and Apple states it is aware of a report that the issue may have been actively exploited.
Description
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityKernel-privilege code execution with confirmed in-the-wild exploitation and CISA KEV listing, though it requires local code execution and no ransomware use is documented.
What it is
An out-of-bounds write (CWE-787) in Apple's kernel was addressed with improved bounds checks in macOS Monterey 12.6, macOS Big Sur 11.7, iOS 15.7/iPadOS 15.7 and iOS 16. A local application can trigger the flaw to execute arbitrary code with kernel privileges, and Apple states it is aware of a report that the issue may have been actively exploited.
Impact
An attacker who can run code on the device gains kernel-level code execution, effectively full control of the operating system and its protections.
Attack surface
The CVSS vector is local (AV:L) with low privileges (PR:L) and no user interaction (UI:N), so the flaw is reached by a malicious or compromised application already running on the device rather than over the network.
Exploitation
CVE-2022-32917 is listed in CISA KEV with a remediation due date of 2022-10-05, and Apple acknowledges a report of active exploitation; EPSS 30-day probability is about 5.6 percent (92.5th percentile). No ransomware campaign use is documented.
What to do
- Update to the fixed releases: macOS Monterey 12.6, macOS Big Sur 11.7, iOS 15.7/iPadOS 15.7 or iOS 16, per Apple advisories HT213443 through HT213446.
- Prioritize patching for devices exposed to untrusted or sideloaded applications, and enforce a minimum OS version for managed fleets.
- Restrict installation of applications to trusted sources and review mobile device management policies that allow untrusted app distribution.
- Monitor Apple security advisories for follow-up fixes, since this class of kernel memory corruption often recurs across releases.
Detection
- Hunt for unexpected kernel panics or crashes on Apple endpoints, which can accompany out-of-bounds write exploitation.
- Review endpoint telemetry for unusual processes gaining kernel-level activity or loading unexpected kernel extensions.
- Check asset inventories against the fixed OS versions to find unpatched iPhones, iPads and Macs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-32917 to the Known Exploited Vulnerabilities catalog on 14 September 2022 as "Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 5 October 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-32917 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-32917), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.