Apple Releases iOS 15.5 and iPadOS 15.5

    Apple Releases iOS 15.5 and iPadOS 15.5

    Apple Releases iOS 15.5 and iPadOS 15.5


    Posted: 16 May 2022

    Apple today released iOS 15.5 and iPadOS 15.5, the fifth major updates to the iOS and iPadOS 15 operating systems that were initially released in September 2021. iOS and iPadOS 15.5 come a little over two months after the launch of iOS 15.4 and iPadOS 15.4.

    iOS 15.5 and iPadOS 15.5

    AppleAVD
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: A use after free issue was addressed with improved memory management.
    CVE-2022-26702: an anonymous researcher

    AppleGraphicsControl
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: Processing a maliciously crafted image may lead to arbitrary code execution
    Description: A memory corruption issue was addressed with improved input validation.
    CVE-2022-26751: Michael DePlante (@izobashi) of Trend Micro Zero Day Initiative

    AVEVideoEncoder
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: An out-of-bounds write issue was addressed with improved bounds checking.
    CVE-2022-26736: an anonymous researcher
    CVE-2022-26737: an anonymous researcher
    CVE-2022-26738: an anonymous researcher
    CVE-2022-26739: an anonymous researcher
    CVE-2022-26740: an anonymous researcher

    DriverKit
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious application may be able to execute arbitrary code with system privileges
    Description: An out-of-bounds access issue was addressed with improved bounds checking.
    CVE-2022-26763: Linus Henze of Pinauten GmbH (pinauten.de)

    GPU Drivers
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: A memory corruption issue was addressed with improved state management.
    CVE-2022-26744: an anonymous researcher

    ImageIO
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
    Description: An integer overflow issue was addressed with improved input validation.
    CVE-2022-26711: actae0n of Blacksun Hackers Club working with Trend Micro Zero Day Initiative

    IOKit
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: A race condition was addressed with improved locking.
    CVE-2022-26701: chenyuwang (@mzzzz__) of Tencent Security Xuanwu Lab

    IOMobileFrameBuffer
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: A memory corruption issue was addressed with improved state management.
    CVE-2022-26768: an anonymous researcher

    IOSurfaceAccelerator
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious application may be able to execute arbitrary code with kernel privileges
    Description: A memory corruption issue was addressed with improved state management.
    CVE-2022-26771: an anonymous researcher

    Kernel
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: A memory corruption issue was addressed with improved validation.
    CVE-2022-26714: Peter Nguyễn Vũ Hoŕng (@peternguyen14) of STAR Labs (@starlabs_sg)

    Kernel
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An application may be able to execute arbitrary code with kernel privileges
    Description: A use after free issue was addressed with improved memory management.
    CVE-2022-26757: Ned Williamson of Google Project Zero

    Kernel
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations
    Description: A memory corruption issue was addressed with improved validation.
    CVE-2022-26764: Linus Henze of Pinauten GmbH (pinauten.de)

    Kernel
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
    Description: A race condition was addressed with improved state handling.
    CVE-2022-26765: Linus Henze of Pinauten GmbH (pinauten.de)

    LaunchServices
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A sandboxed process may be able to circumvent sandbox restrictions
    Description: An access issue was addressed with additional sandbox restrictions on third-party applications.
    CVE-2022-26706: Arsenii Kostromin (0x3c3e)

    libxml2
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
    Description: A use after free issue was addressed with improved memory management.
    CVE-2022-23308

    Notes
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: Processing a large input may lead to a denial of service
    Description: This issue was addressed with improved checks.
    CVE-2022-22673: Abhay Kailasia (@abhay_kailasia) of Lakshmi Narain College Of Technology Bhopal

    Safari Private Browsing
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious website may be able to track users in Safari private browsing mode
    Description: A logic issue was addressed with improved state management.
    CVE-2022-26731: an anonymous researcher

    Security
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious app may be able to bypass signature validation
    Description: A certificate parsing issue was addressed with improved checks.
    CVE-2022-26766: Linus Henze of Pinauten GmbH (pinauten.de)

    Shortcuts
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A person with physical access to an iOS device may be able to access photos from the lock screen
    Description: An authorization issue was addressed with improved state management.
    CVE-2022-26703: Salman Syed (@slmnsd551)

    WebKit
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: Processing maliciously crafted web content may lead to code execution
    Description: A memory corruption issue was addressed with improved state management.
    WebKit Bugzilla: 238178
    CVE-2022-26700: ryuzaki

    WebKit
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: Processing maliciously crafted web content may lead to arbitrary code execution
    Description: A use after free issue was addressed with improved memory management.
    WebKit Bugzilla: 236950
    CVE-2022-26709: Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher lab
    WebKit Bugzilla: 237475
    CVE-2022-26710: Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher lab
    WebKit Bugzilla: 238171
    CVE-2022-26717: Jeonghoon Shin of Theori

    WebKit
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: Processing maliciously crafted web content may lead to arbitrary code execution
    Description: A memory corruption issue was addressed with improved state management.
    WebKit Bugzilla: 238183
    CVE-2022-26716: SorryMybad (@S0rryMybad) of Kunlun Lab
    WebKit Bugzilla: 238699
    CVE-2022-26719: Dongzhuo Zhao working with ADLab of Venustech

    WebRTC
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: Video self-preview in a webRTC call may be interrupted if the user answers a phone call
    Description: A logic issue in the handling of concurrent media was addressed with improved state handling.
    WebKit Bugzilla: 237524
    CVE-2022-22677: an anonymous researcher

    Wi-Fi
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious application may disclose restricted memory
    Description: A memory corruption issue was addressed with improved validation.
    CVE-2022-26745: an anonymous researcher

    Wi-Fi
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious application may be able to elevate privileges
    Description: A memory corruption issue was addressed with improved state management.
    CVE-2022-26760: 08Tc3wBB of ZecOps Mobile EDR Team

    Wi-Fi
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A remote attacker may be able to cause a denial of service
    Description: This issue was addressed with improved checks.
    CVE-2015-4142: Kostya Kortchinsky of Google Security Team

    Wi-Fi
    Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
    Impact: A malicious application may be able to execute arbitrary code with system privileges
    Description: A memory corruption issue was addressed with improved memory handling.
    CVE-2022-26762: Wang Yu of Cyberserval

    Read more:
    Brink's Avatar Posted By: Brink
    16 May 2022


  1. Posts : 2,585
    Win 11
       #1

    Also watch OS upgrade to (I think) 8.5.
      My Computers


  2. Posts : 2,554
    Windows 10 Pro 64bit
       #2

    Installing now.
      My Computer


  3. Posts : 402
    Windows 10 Home 64-bit operating system, x64-based processor
       #3

    I just installed 15.4.1 this past weekend. !
    I can remember installing new updates VIA iTunes on my PC without having to turn off the passcode. Last few years, now you have too going thru iTunes. Such a pain!
      My Computer


  4. Posts : 2,554
    Windows 10 Pro 64bit
       #4

    fireberd said:
    Also watch OS upgrade to (I think) 8.5.
    Current iWatch OS is 8.6 - checked on my iPhone. There’s usually an update released along with the other iOS versions though.
      My Computer


  5. Posts : 936
    xp
       #5

    I just did the updates to 15.4.1 and here I go again :C Maybe if I wasn't doing 12 iPhones and an iPad it wouldn't be so bad ? Batwife is going to visit her family in the Philippines so she's bringing all our old phones that we replaced to give to them. With the 6s and original SE models I'm afraid they've about reached their update limits. Not that the OS doesn't still run smooth enough, it's just when a lot of the memory is in use the update takes forever and the phone overheats. I had one 6s go into a unrecoverable bootloop going to 14.5.1 The 7 plus and later models are all updating smoothly though
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 02:36.
Find Us




Windows 10 Forums