Description:
Apple has released iOS 15.5 and iPadOS 15.5 to fix the vulnerabilities in various Apple devices. The list of vulnerability information can be found at:
https://support.apple.com/en-us/HT213258
Affected Systems:
- iPhone 6s and later
- iPad 5th generation and later, Air 2 and later, mini 4 and later, Pro (all models)
- iPod touch (7th generation)
Impact:
A successful exploitation could lead to arbitrary code execution, denial of service, information disclosure, privilege escalation or security restriction bypass on an affected device.
Recommendation:
Apple has released new version of iOS and iPadOS to address the issue.
The updates can be obtained through the auto-update mechanism. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
More Information:
- https://support.apple.com/en-us/HT213258
- https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20220517
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4142
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22673
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22677
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23308
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26700 (to CVE-2022-26703)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26706
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26709 (to CVE-2022-26711)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26714
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26716
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26717
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26719
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26731
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26736 (to CVE-2022-26740)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26744
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26745
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26751
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26757
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26760
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26762 (to CVE-2022-26766)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26768
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26771