CVE-2022-42827 is an out-of-bounds write vulnerability affecting Apple iOS and iPadOS that could allow an application to execute arbitrary code with kernel privileges. This high-severity flaw (CVSS 7.8) requires user interaction (UI:R) for exploitation, but once triggered, it grants full confidentiality, integrity, and availability impact (C:H/I:H/A:H). Apple has confirmed active exploitation of this zero-day vulnerability in the wild, though no public exploit code is currently available. The issue is addressed in iOS 15.7.1, iPadOS 15.7.1, iOS 16.1, and iPadOS 16.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.7.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.7.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.