About the security content of iOS 15.4.1 and iPadOS 15.4.1
support.apple.com
About the security content of iOS 15.4.1 and iPadOS 15.4.1
1–10 of 28 posts
Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#2An application may be able to execute arbitrary code with kernel privileges.
Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#3More info on the exploit that was patched found here: https://cwe.mitre.org/data/definitions/787.html . An application may be able to execute arbitrary code with kernel privileges.
Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#4More info on the exploit that was patched found here: https://cwe.mitre.org/data/definitions/787.html . An application may be able to execute arbitrary code with kernel privileges.
Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#5More info on the exploit that was patched found here: https://cwe.mitre.org/data/definitions/787.html . An application may be able to execute arbitrary code with kernel privileges.
Did you mean to link to a CWE page? This isn't about a specific bug.
> An out-of-bounds write issue was addressed with improved bounds checking. (CVE-2022-22675)
Which sounds exactly like a CWE-787 candidate.
Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#6Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#7Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#8Earlier quoted context omitted.
Did you mean to link to a CWE page? This isn't about a specific bug.
Isn’t it? The patch is specifically to address: > An out-of-bounds write issue was addressed with improved bounds checking. (CVE-2022-22675) Which sounds exactly like a CWE-787 candidate.
Re: About the security content of iOS 15.4.1 and iPadOS 15.4.1
#9Earlier quoted context omitted.
Isn’t it? The patch is specifically to address: > An out-of-bounds write issue was addressed with improved bounds checking. (CVE-2022-22675) Which sounds exactly like a CWE-787 candidate.
gzer0's comment is a bit confusing. It could either be interpreted as saying "here's more info about this exact vulnerability" or "here's more info about this category of vulnerabilities". EE84M3i interpreted the comment as the first, but then saw the link is actually the second, and thought maybe EE84M3i made a mistake with the comment.
> More info on the exploit that was patched found here
might have inferred the category of vulnerabilities more.