{"id":28305,"date":"2022-07-24T09:08:42","date_gmt":"2022-07-24T05:08:42","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167788\/APPLE-SA-2022-07-20-3.txt"},"modified":"2022-07-24T14:00:42","modified_gmt":"2022-07-24T09:30:42","slug":"apple-security-advisory-2022-07-20-3","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-2022-07-20-3\/","title":{"rendered":"Apple Security Advisory 2022-07-20-3"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p>APPLE-SA-2022-07-20-3 macOS Big Sur 11.6.8<\/p>\n<p>macOS Big Sur 11.6.8 addresses the following issues.<br \/>\nInformation about the security content is also available at<br \/>\nhttps:\/\/support.apple.com\/HT213344.<\/p>\n<p>APFS<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app with root privileges may be able to execute arbitrary<br \/>\ncode with kernel privileges<br \/>\nDescription: The issue was addressed with improved memory handling.<br \/>\nCVE-2022-32832: Tommy Muir (@Muirey03)<\/p>\n<p>AppleMobileFileIntegrity<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to gain root privileges<br \/>\nDescription: An authorization issue was addressed with improved state<br \/>\nmanagement.<br \/>\nCVE-2022-32826: Mickey Jin (@patch1t) of Trend Micro<\/p>\n<p>AppleScript<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Processing a maliciously crafted AppleScript binary may<br \/>\nresult in unexpected termination or disclosure of process memory<br \/>\nDescription: This issue was addressed with improved checks.<br \/>\nCVE-2022-32797: Mickey Jin (@patch1t), Ye Zhang (@co0py_Cat) of Baidu<br \/>\nSecurity, Mickey Jin (@patch1t) of Trend Micro<\/p>\n<p>AppleScript<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Processing a maliciously crafted AppleScript binary may<br \/>\nresult in unexpected termination or disclosure of process memory<br \/>\nDescription: An out-of-bounds read issue was addressed with improved<br \/>\ninput validation.<br \/>\nCVE-2022-32853: Ye Zhang (@co0py_Cat) of Baidu Security<br \/>\nCVE-2022-32851: Ye Zhang (@co0py_Cat) of Baidu Security<\/p>\n<p>AppleScript<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Processing a maliciously crafted AppleScript binary may<br \/>\nresult in unexpected termination or disclosure of process memory<br \/>\nDescription: An out-of-bounds read issue was addressed with improved<br \/>\nbounds checking.<br \/>\nCVE-2022-32831: Ye Zhang (@co0py_Cat) of Baidu Security<\/p>\n<p>Audio<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to disclose kernel memory<br \/>\nDescription: The issue was addressed with improved memory handling.<br \/>\nCVE-2022-32825: John Aakerblom (@jaakerblom)<\/p>\n<p>Audio<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to execute arbitrary code with kernel<br \/>\nprivileges<br \/>\nDescription: An out-of-bounds write issue was addressed with improved<br \/>\ninput validation.<br \/>\nCVE-2022-32820: an anonymous researcher<\/p>\n<p>Calendar<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to access sensitive user information<br \/>\nDescription: The issue was addressed with improved handling of<br \/>\ncaches.<br \/>\nCVE-2022-32805: Csaba Fitzl (@theevilbit) of Offensive Security<\/p>\n<p>Calendar<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to access user-sensitive data<br \/>\nDescription: An information disclosure issue was addressed by<br \/>\nremoving the vulnerable code.<br \/>\nCVE-2022-32849: Joshua Jones<\/p>\n<p>CoreText<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: A remote user may cause an unexpected app termination or<br \/>\narbitrary code execution<br \/>\nDescription: The issue was addressed with improved bounds checks.<br \/>\nCVE-2022-32839: STAR Labs (@starlabs_sg)<\/p>\n<p>FaceTime<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app with root privileges may be able to access private<br \/>\ninformation<br \/>\nDescription: This issue was addressed by enabling hardened runtime.<br \/>\nCVE-2022-32781: Wojciech Regu\u0142a (@_r3ggi) of SecuRing<\/p>\n<p>File System Events<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to gain root privileges<br \/>\nDescription: A logic issue was addressed with improved state<br \/>\nmanagement.<br \/>\nCVE-2022-32819: Joshua Mason of Mandiant<\/p>\n<p>ICU<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Processing maliciously crafted web content may lead to<br \/>\narbitrary code execution<br \/>\nDescription: An out-of-bounds write issue was addressed with improved<br \/>\nbounds checking.<br \/>\nCVE-2022-32787: Dohyun Lee (@l33d0hyun) of SSD Secure Disclosure Labs<br \/>\n&amp; DNSLab, Korea Univ.<\/p>\n<p>ImageIO<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Processing an image may lead to a denial-of-service<br \/>\nDescription: A null pointer dereference was addressed with improved<br \/>\nvalidation.<br \/>\nCVE-2022-32785: Yi\u011fit Can YILMAZ (@yilmazcanyigit)<\/p>\n<p>Intel Graphics Driver<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to execute arbitrary code with kernel<br \/>\nprivileges<br \/>\nDescription: The issue was addressed with improved memory handling.<br \/>\nCVE-2022-32812: Yinyi Wu (@3ndy1), ABC Research s.r.o.<\/p>\n<p>Intel Graphics Driver<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to execute arbitrary code with kernel<br \/>\nprivileges<br \/>\nDescription: A memory corruption vulnerability was addressed with<br \/>\nimproved locking.<br \/>\nCVE-2022-32811: ABC Research s.r.o<\/p>\n<p>Kernel<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app with root privileges may be able to execute arbitrary<br \/>\ncode with kernel privileges<br \/>\nDescription: The issue was addressed with improved memory handling.<br \/>\nCVE-2022-32815: Xinru Chi of Pangu Lab<br \/>\nCVE-2022-32813: Xinru Chi of Pangu Lab<\/p>\n<p>libxml2<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to leak sensitive user information<br \/>\nDescription: A memory initialization issue was addressed with<br \/>\nimproved memory handling.<br \/>\nCVE-2022-32823<\/p>\n<p>PackageKit<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to modify protected parts of the file<br \/>\nsystem<br \/>\nDescription: An issue in the handling of environment variables was<br \/>\naddressed with improved validation.<br \/>\nCVE-2022-32786: Mickey Jin (@patch1t)<\/p>\n<p>PackageKit<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to modify protected parts of the file<br \/>\nsystem<br \/>\nDescription: This issue was addressed with improved checks.<br \/>\nCVE-2022-32800: Mickey Jin (@patch1t)<\/p>\n<p>PluginKit<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to read arbitrary files<br \/>\nDescription: A logic issue was addressed with improved state<br \/>\nmanagement.<br \/>\nCVE-2022-32838: Mickey Jin (@patch1t) of Trend Micro<\/p>\n<p>PS Normalizer<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Processing a maliciously crafted Postscript file may result<br \/>\nin unexpected app termination or disclosure of process memory<br \/>\nDescription: An out-of-bounds write issue was addressed with improved<br \/>\nbounds checking.<br \/>\nCVE-2022-32843: Kai Lu of Zscaler&#8217;s ThreatLabz<\/p>\n<p>Software Update<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: A user in a privileged network position can track a user\u2019s<br \/>\nactivity<br \/>\nDescription: This issue was addressed by using HTTPS when sending<br \/>\ninformation over the network.<br \/>\nCVE-2022-32857: Jeffrey Paul (sneak.berlin)<\/p>\n<p>Spindump<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to overwrite arbitrary files<br \/>\nDescription: This issue was addressed with improved file handling.<br \/>\nCVE-2022-32807: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab<\/p>\n<p>Spotlight<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to gain elevated privileges<br \/>\nDescription: A validation issue in the handling of symlinks was<br \/>\naddressed with improved validation of symlinks.<br \/>\nCVE-2022-26704: Joshua Mason of Mandiant<\/p>\n<p>TCC<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to access sensitive user information<br \/>\nDescription: An access issue was addressed with improvements to the<br \/>\nsandbox.<br \/>\nCVE-2022-32834: Zhipeng Huo (@R3dF09) and Yuebin Sun (@yuebinsun2020)<br \/>\nof Tencent Security Xuanwu Lab (xlab.tencent.com)<\/p>\n<p>Vim<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: Multiple issues in Vim<br \/>\nDescription: Multiple issues were addressed by updating Vim.<br \/>\nCVE-2022-0156<br \/>\nCVE-2022-0158<\/p>\n<p>Wi-Fi<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: A remote user may be able to cause unexpected system<br \/>\ntermination or corrupt kernel memory<br \/>\nDescription: This issue was addressed with improved checks.<br \/>\nCVE-2022-32847: Wang Yu of Cyberserval<\/p>\n<p>Windows Server<br \/>\nAvailable for: macOS Big Sur<br \/>\nImpact: An app may be able to capture a user\u2019s screen<br \/>\nDescription: A logic issue was addressed with improved checks.<br \/>\nCVE-2022-32848: Jeremy Legendre of MacEnhance<\/p>\n<p>macOS Big Sur 11.6.8 may be obtained from the Mac App Store or<br \/>\nApple&#8217;s Software Downloads web site:<br \/>\nhttps:\/\/support.apple.com\/downloads\/<br \/>\nAll information is also posted on the Apple Security Updates<br \/>\nweb site: https:\/\/support.apple.com\/en-us\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>\nand details are available at:<br \/>\nhttps:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEePiLW1MrMjw19XzoeC9qKD1prhgFAmLYf6sACgkQeC9qKD1p<br \/>\nrhgOJBAAtzyKOqdTnnBbwbFoG\/HoZIbCVSVOtI5VIGH1weMQ72R3X2tXB5yTlpto<br \/>\n3l\/eoMe0\/covxipiZ+CvTh9tM5ZfV3IxN4bpsbxew1R\/s81YE2K55dFp5+4zzqgh<br \/>\nYyWrx8SntngP9PywAdKa+GRZrW7R95oNp2UTwifcQvFPs40F\/OPrNQm23Xkmqsx0<br \/>\nzNNvMmqPaeCU8mgIOadO\/uv626LjnkyKdwHKM3VBxGmklNEddQDjjoWcYugH7QYj<br \/>\ne28EpKINEYfGVP\/5n4uSeP6+kXmJj9nLzdKzfBD78gyBu5NX3Ai5Wh1BbsFMoFYE<br \/>\nwcqlgEjMk3440babLb9kSRm81NX+EPgJLtjVPNRIrqs8pTh95CcDTRsotDUDl03R<br \/>\nBrP6XGyXiS+3XyhdbamJDG9pCthJdo455XaYOlmzgIfgTJMkX3kdxiMAgGvbkPVl<br \/>\n3IesUuChRvi6pZwTWXN4k5Rn9epZSV+9HaYplnFPScJpYeLzUKThz1P2KbMTd0CT<br \/>\nfiBU+fxwQqfzGRX3gyzRz0DMqiGdk0PnO9pfWND+9lQDyht7s73XnZrVOnPZHGYC<br \/>\ntiNdrEHm+4WKaEwl\/5invCZ8vPaiJ9cTH\/aSbeRkeqR8ilDQMIhm2xooSP8Sd00E<br \/>\ngTOoTOANfxrOqkFWhj0HQEq5OmCeALkE8BqiLuOVVIrN4e2LgPg=<br \/>\n=6wU+<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 APPLE-SA-2022-07-20-3 macOS Big Sur 11.6.8 macOS Big Sur 11.6.8 addresses the following issues. Information about the security content is also available at https:\/\/support.apple.com\/HT213344. APFS Available for: macOS Big Sur Impact: An app with root privileges may be able to execute arbitrary code with kernel privileges Description: The issue was &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-28305","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/28305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=28305"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/28305\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=28305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=28305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=28305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}