10-10-2024, 10:08 PM
Tested devices:
iPhone 12 pro (iPhone 13,3) with iOS 15.5
iPad pro (iPad8,10) with iPadOS 15.5
iPhone 11 pro (iPhone 12,3) with iOS 15.4.1
MacBookAir10,1 M1 with macOS 12.4
Code (github):
iPhone 12 pro (iPhone 13,3) with iOS 15.5
iPad pro (iPad8,10) with iPadOS 15.5
iPhone 11 pro (iPhone 12,3) with iOS 15.4.1
MacBookAir10,1 M1 with macOS 12.4
- CVE-2022-32845
: aned signature check bypass for model.hwx.
- CVE-2022-32948
: DeCxt::FileIndexToWeight() OOB Read due to lack of array index validation.
- CVE-2022-42805
: ZinComputeProgramUpdateMutables() potential arbitrary read due to Integer overflow issue.
- CVE-2022-32899
: DeCxt::RasterizeScaleBiasData() Buffer underflow due to integer overflow issue.
Code (github):
![[Image: text.gif]](https://external-content.duckduckgo.com/iu/?u=https://i.postimg.cc/Kv4Zkxw9/text.gif)