Description:
Apple has released iOS 15.5 and iPadOS 15.5 to fix the vulnerabilities in various Apple devices. The list of vulnerability information can be found at:
https://support.apple.com/en-us/HT213258
 
Affected Systems:
- iPhone 6s and later
 
- iPad 5th generation and later, Air 2 and later, mini 4 and later, Pro (all models)
 
- iPod touch (7th generation)
 
 
Impact:
A successful exploitation could lead to arbitrary code execution, denial of service, information disclosure, privilege escalation or security restriction bypass on an affected device.
 
Recommendation:
Apple has released new version of iOS and iPadOS to address the issue.
The updates can be obtained through the auto-update mechanism. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
 
More Information:
- https://support.apple.com/en-us/HT213258
 
- https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20220517
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4142
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22673
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22677
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23308
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26700 (to CVE-2022-26703)
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26706
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26709 (to CVE-2022-26711)
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26714
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26716
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26717
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26719
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26731
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26736 (to CVE-2022-26740)
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26744
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26745
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26751
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26757
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26760
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26762 (to CVE-2022-26766)
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26768
 
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26771