CVE-2022-32947 is a vulnerability in Apple operating systems (iOS, iPadOS, macOS, watchOS) that allows an application to execute arbitrary code with kernel privileges due to improper memory handling. The vulnerability was addressed by Apple with improved memory management in iOS 16.1, iPadOS 16, macOS Ventura 13, and watchOS 9.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a full exploit chain for CVE-2022-32947, a vulnerability in the Apple GPU driver on macOS 13.0 beta 5 (Apple Silicon). The exploit is implemented in C, Objective-C, and Metal shading language, and is organized under the 'demo_exploit' directory. The main entry point is 'demo_exploit/main.c', which orchestrates the attack in several stages: 1. It initializes the GPU and Metal environment using Objective-C code in 'runner.m'. 2. Stage 1 exploits the GPU to gain access to a page table, using Metal compute shaders ('shaders.metal'). 3. Stage 2 maps all physical memory as read/write, allowing arbitrary kernel memory access. 4. The exploit locates the kernel base and page tables, then walks the kernel's process list to find its own process structure. 5. It overwrites the process credentials in kernel memory to set UID and GID to 0 (root). 6. Finally, it spawns a root shell ('/bin/sh') as proof of successful privilege escalation. The exploit is highly technical and targets a specific macOS beta version on Apple Silicon. It requires local access and does not use any network endpoints. The repository also contains a 'slides' directory with a Reveal.js-based presentation explaining the vulnerability and exploit, but the actual exploit code is in the 'demo_exploit' directory. The exploit is operational and provides a working local privilege escalation chain for research and demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.