Apple has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. Note: Apple notes they are aware of a report that states CVE-2022-22675 may have been actively exploited. CVE-2022-22675 affects watchOS, tvOS, and macOS Big Sur.
CISA encourages users and administrators to review the Apple security pages for the following products and apply the necessary updates.
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
SYSTEMS AFFECTED:
RISK:
Government:
Businesses:
Home users: High
TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Adobe Products, the most severe of which could allow for arbitrary code execution. Details of these vulnerabilities are as follows:
RECOMMENDATIONS:
We recommend the following actions be taken:
REFERENCES:
Apple:
About the security content of watchOS 8.6 - Apple Support
About the security content of tvOS 15.5 - Apple Support
About the security content of Security Update 2022-004 Catalina - Apple Support
About the security content of macOS Big Sur 11.6.6 - Apple Support
About the security content of macOS Monterey 12.4 - Apple Support
About the security content of iOS 15.5 and iPadOS 15.5 - Apple Support
About the security content of Xcode 13.4 - Apple Support
Apple emergency update fixes zero-day used to hack Macs, Watches (bleepingcomputer.com)
CVE:
CVE- CVE-2022-22675 (mitre.org)