Apple has released security updates for iOS and iPadOS 15.3, as well as macOS Monterey 12.2, to address a vulnerability that the firm claims is being abused in the wild.
The issue, dubbed CVE-2022-22587, was separately disclosed to Apple by an anonymous researcher, Siddharth Aeri, and Meysam Firouzi. Firouzi, who works on automotive security at the Mercedes-Benz Innovation Lab, told that he discovered the flaw by fuzzing the kernel and performing static analysis.
According to Apple’s security alert, the flaw is caused by a memory corruption vulnerability in iOS and macOS. A malicious application exploiting the issue might run arbitrary code with elevated kernel privileges. Firouzi and Aeri have provided proof-of-concept code for the zero-day. Firouzi indicated that the vulnerability he uncovered will be part of a chain of exploits.
An attacker would need to obtain remote code execution via NSO Group’s PDF exploit and “then leverage my vulnerability to gain greater access to the device,” according to Firouzi.
Three months ago, the security researcher submitted the vulnerability to Trend Micro’s Zero Day Initiative, but received no response.
“They didn’t respond to me for like two months, so I decided to submit [the vulnerability] straight to Apple,” Firouzi explained.
Firouzi described his work on Apple security as a hobby. Apple’s security patches address a number of critical vulnerabilities, many of which may be exploited to execute arbitrary code with elevated privileges.
Apple has also corrected the Safari WebKit flaw that permitted cross-origin monitoring of users’ internet activity, as well as enhanced input validation for the IndexedDB application programming interface storage component.


