An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
Update Apple/iOS and iPadOS to 15.7; Apple/iOS and iPadOS to 16.5; Apple/macOS to 12.6; Apple/macOS to 13.4; Apple/macOS to 11.7; Apple/watchOS to 8.8; Apple/watchOS to 9.5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCVE Program Container affects Apple/iOS and iPadOS (generic), Apple/iOS and iPadOS (generic), Apple/macOS (generic), Apple/macOS (generic), Apple/macOS (generic), Apple/watchOS (generic), Apple/watchOS (generic). Severity is high. This vulnerability is known to be exploited in the wild. An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
Update Apple/iOS and iPadOS to 15.7; Apple/iOS and iPadOS to 16.5; Apple/macOS to 12.6; Apple/macOS to 13.4; Apple/macOS to 11.7; Apple/watchOS to 8.8; Apple/watchOS to 9.5 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCVE Program Container affects Apple/iOS and iPadOS (generic), Apple/iOS and iPadOS (generic), Apple/macOS (generic), Apple/macOS (generic), Apple/macOS (generic), Apple/watchOS (generic), Apple/watchOS (generic). Severity is high. This vulnerability is known to be exploited in the wild. An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Apple/iOS and iPadOSgeneric |
|---|
| >=unspecified <15.7 |
| 15.7 |
| Apple/iOS and iPadOSgeneric | >=unspecified <16.5 | 16.5 |
|---|
| Apple/macOSgeneric | >=unspecified <12.6 | 12.6 |
|---|
| Apple/macOSgeneric | >=unspecified <13.4 | 13.4 |
|---|
| Apple/macOSgeneric | >=unspecified <11.7 | 11.7 |
|---|
| Apple/watchOSgeneric | >=unspecified <8.8 | 8.8 |
|---|
| Apple/watchOSgeneric | >=unspecified <9.5 | 9.5 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Apple/iOS and iPadOSgeneric |
|---|
| >=unspecified <15.7 |
| 15.7 |
| Apple/iOS and iPadOSgeneric | >=unspecified <16.5 | 16.5 |
|---|
| Apple/macOSgeneric | >=unspecified <12.6 | 12.6 |
|---|
| Apple/macOSgeneric | >=unspecified <13.4 | 13.4 |
|---|
| Apple/macOSgeneric | >=unspecified <11.7 | 11.7 |
|---|
| Apple/watchOSgeneric | >=unspecified <8.8 | 8.8 |
|---|
| Apple/watchOSgeneric | >=unspecified <9.5 | 9.5 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard