AppleがiPhoneやiPadなど向け最新プラットフォーム「iOS 16.5」と「iPadOS 16.5」を提供開始!機能向上および不具合や脆弱性の修正
AppleがiPhoneなど向けiOS 16.5とiPadOS 16.5をリリース! |
Appleは18日(現地時間)、同社が販売するスマートフォン(スマホ)「iPhone」シリーズ向けプラットフォーム「iOS」とタブレット「iPad」シリーズ向けプラットフォーム「iPadOS」の最新バージョン「iOS 16.5(20F66)」および「iPadOS 16.5(20F66)」を提供開始したとお知らせしています。
変更点はまれますLGBTQ+のコミュニティーと文化を称える新しいプライドセレブレーションの壁紙をロック画面に追加したほか、Spotlightが反応しなくなることがある問題やスクリーンタイムの設定がリセットされる、またはすべてのデバイスに同期されないことがある問題などの各種不具合の修正、さらに多数のセキュリティーアップデートが実施されているとのことです。
その他、別途紹介しているようにiOS 16やiPadOS 16に非対応なiPhone 6sやiPhone 7、iPhone SE(第1世代)、iPad Air 2、iPad mini 2など向け「iOS 15.7.6」および「iPadOS 15.7.6」が提供開始されているほか、スマートウォッチ向け「watchOS 9.5」やSTB向け「tvOS 16.5」、パソコン向け「macOS Ventura 13.4」および「macOS Monterey 12.6.6」、「macOS Big Sur 11.7.7」なども配信開始されています。
iPhone向けのiOSの最新メジャーバージョンとして昨年9月に提供開始されたiOS 16、iPad向けのiPadOSの最新メジャーバージョンとして昨年10月に提供開始されたiPadOS 16ですが、その後にiPadOS 16.1のリリースに合わせてiOS 16.1が提供開始され、さらにフリーボードAppなどの新機能が追加されたiOS 16.2およびiPadOS 16.2、さらにHomePod(第2世代)に対応するなどのiOS 16.3およびiPadOS 16.3が提供されてきました。
さらに携帯電話回線による音声通話において周囲のノイズを低減して声を分離して相手に伝わりやすくする機能などの新機能が追加されたiOS 16.4およびiPadOS 16.4が配信され、さらにその不具合や脆弱性を修正したiOS 16.4.1やiPadOS 16.4.1がリリースされ、それに対して初の緊急セキュリティーアップデートとして「iOS 16.4.1 (a)」と「iPadOS 16.4.1 (a)」が配信されていましたが、今回、さらにiOS 16.5とiPadOS 16.5が配信開始されました。iOS 16およびiPadOS 16の対象機種は以下の通り。
<iOS 16対応製品>
・iPhone 14
・iPhone 14 Plus
・iPhone 14 Pro
・iPhone 14 Pro Max
・iPhone 13
・iPhone 13 mini
・iPhone 13 Pro
・iPhone 13 Pro Max
・iPhone 12
・iPhone 12 mini
・iPhone 12 Pro
・iPhone 12 Pro Max
・iPhone 11
・iPhone 11 Pro
・iPhone 11 Pro Max
・iPhone XS
・iPhone XS Max
・iPhone XR
・iPhone X
・iPhone 8
・iPhone 8 Plus
・iPhone SE(第2世代)
・iPhone SE(第3世代)
<iPadOS 16対応製品>
・12.9インチiPad Pro(第6世代)
・12.9インチiPad Pro(第5世代)
・12.9インチiPad Pro(第4世代)
・12.9インチiPad Pro(第3世代)
・12.9インチiPad Pro(第2世代)
・12.9インチiPad Pro(第1世代)
・11インチiPad Pro(第4世代)
・11インチiPad Pro(第3世代)
・11インチiPad Pro(第2世代)
・11インチiPad Pro(第1世代)
・10.5インチiPad Pro
・9.7インチiPad Pro
・iPad Air(第5世代)
・iPad Air(第4世代)
・iPad Air(第3世代)
・iPad mini(第6世代)
・iPad mini(第5世代)
・iPad(第10世代)
・iPad(第9世代)
・iPad(第8世代)
・iPad(第7世代)
・iPad(第6世代)
・iPad(第5世代)
更新は従来通り各製品本体のみでOTA(On-The-Air)によりダウンロードで行え、方法としては、「設定」→「一般」→「ソフトウェア・アップデート」から行え、単体でアップデートする場合のダウンロードサイズは手持ちのiPhone 13 Pro MaxでiOS 16.4.1 (a)からだと760.6MBとなっています。またiTunesをインストールしたWindowsおよびMacとUSB-Lightningケーブルで接続しても実施できます。なお、Appleが案内しているアップデートの内容およびセキュリティーコンテンツの修正は以下の通り。
iOS 16.5
このアップデートには、iPhone用の機能向上、バグ修正、およびセキュリティアップデートが含まれています。
このアップデートには、以下の機能強化とバグ修正が含まれます:
・LGBTQ+のコミュニティと文化をたたえる、新しいプライドセレブレーションの壁紙をロック画面に追加
・Spotlightが反応しなくなることがある問題を修正
・CarPlayの“ポッドキャスト”でコンテンツが読み込まれないことがある問題に対応
・スクリーンタイムの設定がリセットされる、またはすべてのデバイスに同期されないことがある問題を修正
一部の機能は、地域やAppleデバイスによっては使用できない場合があります。Appleソフトウェアアップデートのセキュリティコンテンツについては、以下のWebサイトをご覧ください:
https://support.apple.com/ja-jp/HT201222
iPadOS 16.5
このアップデートには、iPad用の機能向上、バグ修正、およびセキュリティアップデートが含まれています。
このアップデートには、以下の機能強化とバグ修正が含まれます:
・LGBTQ+のコミュニティと文化をたたえる、新しいプライドセレブレーションの壁紙をロック画面に追加
・Spotlightが反応しなくなることがある問題を修正
・CarPlayの“ポッドキャスト”でコンテンツが読み込まれないことがある問題に対応
・スクリーンタイムの設定がリセットされる、またはすべてのデバイスに同期されないことがある問題を修正
一部の機能は、地域やAppleデバイスによっては使用できません。Appleソフトウェア・アップデートのセキュリティコンテンツについては、以下のWebサイトをご覧ください:
https://support.apple.com/ja-jp/HT201222
iOS 16.5 and iPadOS 16.5
Released May 18, 2023
- Accessibility
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to bypass Privacy preferences
Description: A privacy issue was addressed with improved private data redaction for log entries.
CVE-2023-32388: Kirin (@Pwnrin)
- Accessibility
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Entitlements and privacy permissions granted to this app may be used by a malicious app
Description: This issue was addressed with improved checks.
CVE-2023-32400: Mickey Jin (@patch1t)
- AppleMobileFileIntegrity
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved entitlements.
CVE-2023-32411: Mickey Jin (@patch1t)
- Associated Domains
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
CVE-2023-32371: James Duffy (mangoSecure)
- Cellular
Available for: iPhone 8 and iPhone X
Impact: A remote attacker may be able to cause arbitrary code execution
Description: The issue was addressed with improved bounds checks.
CVE-2023-32419: Amat Cama of Vigilant Labs
- Core Location
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to read sensitive location information
Description: The issue was addressed with improved handling of caches.
CVE-2023-32399: an anonymous researcher
- CoreServices
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2023-28191: Mickey Jin (@patch1t)
- GeoServices
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to read sensitive location information
Description: A privacy issue was addressed with improved private data redaction for log entries.
CVE-2023-32392: an anonymous researcher
- ImageIO
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing an image may result in disclosure of process memory
Description: An out-of-bounds read was addressed with improved input validation.
CVE-2023-32372: Meysam Firouzi of @R00tkitSMM Mbition mercedes-benz innovation lab working with Trend Micro Zero Day Initiative
- ImageIO
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing an image may lead to arbitrary code execution
Description: A buffer overflow was addressed with improved bounds checking.
CVE-2023-32384: Meysam Firouzi @R00tkitsmm working with Trend Micro Zero Day Initiative
- IOSurfaceAccelerator
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to disclose kernel memory
Description: An out-of-bounds read was addressed with improved input validation.
CVE-2023-32354: Linus Henze of Pinauten GmbH (pinauten.de)
- IOSurfaceAccelerator
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to cause unexpected system termination or read kernel memory
Description: An out-of-bounds read was addressed with improved input validation.
CVE-2023-32420: Linus Henze of Pinauten GmbH (pinauten.de)
- Kernel
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A type confusion issue was addressed with improved checks.
CVE-2023-27930: 08Tc3wBB of Jamf
- Kernel
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A use-after-free issue was addressed with improved memory management.
CVE-2023-32398: Adam Doupe of ASU SEFCOM
- Kernel
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with improved state handling.
CVE-2023-32413: Eloi Benoist-Vanderbeken (@elvanderb) from Synacktiv (@Synacktiv) working with Trend Micro Zero Day Initiative
- LaunchServices
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
CVE-2023-32352: Wojciech Reguła (@_r3ggi) of SecuRing (wojciechregula.blog)
- Metal
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to bypass Privacy preferences
Description: A logic issue was addressed with improved state management.
CVE-2023-32407: Gergely Kalman (@gergely_kalman)
- Model I/O
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing a 3D model may result in disclosure of process memory
Description: An out-of-bounds read was addressed with improved input validation.
CVE-2023-32368: Mickey Jin (@patch1t)
- NetworkExtension
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to read sensitive location information
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2023-32403: an anonymous researcher
- PDFKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Opening a PDF file may lead to unexpected app termination
Description: A denial-of-service issue was addressed with improved memory handling.
CVE-2023-32385: Jonathan Fritz
- Photos
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Shake-to-undo may allow a deleted photo to be re-surfaced without authentication
Description: The issue was addressed with improved checks.
CVE-2023-32365: Jiwon Park
- Photos
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup
Description: The issue was addressed with improved checks.
CVE-2023-32390: Julian Szulc
- Sandbox
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to retain access to system configuration files even after its permission is revoked
Description: An authorization issue was addressed with improved state management.
CVE-2023-32357: Yiğit Can YILMAZ (@yilmazcanyigit), Koh M. Nakagawa of FFRI Security, Inc., Kirin (@Pwnrin), Jeff Johnson (underpassapp.com), and Csaba Fitzl (@theevilbit) of Offensive Security
- Security
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with improved entitlements.
CVE-2023-32367: James Duffy (mangoSecure)
- Shortcuts
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user
Description: The issue was addressed with improved checks.
CVE-2023-32391: Wenchao Li and Xiaolong Bai of Alibaba Group
- Shortcuts
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved entitlements.
CVE-2023-32404: Mickey Jin (@patch1t), Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab (xlab.tencent.com), and an anonymous researcher
- Siri
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: A person with physical access to a device may be able to view contact information from the lock screen
Description: The issue was addressed with improved checks.
CVE-2023-32394: Khiem Tran
- SQLite
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to access data from other apps by enabling additional SQLite logging
Description: This issue was addressed by adding additional SQLite logging restrictions.
CVE-2023-32422: Gergely Kalman (@gergely_kalman)
- StorageKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to modify protected parts of the file system
Description: This issue was addressed with improved entitlements.
CVE-2023-32376: Yiğit Can YILMAZ (@yilmazcanyigit)
- System Settings
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app firewall setting may not take effect after exiting the Settings app
Description: This issue was addressed with improved state management.
CVE-2023-28202: Satish Panduranga and an anonymous researcher
- Telephony
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
CVE-2023-32412: Ivan Fratric of Google Project Zero
- TV App
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to read sensitive location information
Description: The issue was addressed with improved handling of caches.
CVE-2023-32408: an anonymous researcher
- Weather
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to read sensitive location information
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2023-32415: Wojciech Regula of SecuRing (wojciechregula.blog), and an anonymous researcher
- WebKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing web content may disclose sensitive information
Description: An out-of-bounds read was addressed with improved input validation.
WebKit Bugzilla: 255075
CVE-2023-32402: an anonymous researcher
- WebKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing web content may disclose sensitive information
Description: A buffer overflow issue was addressed with improved memory handling.
WebKit Bugzilla: 254781
CVE-2023-32423: Ignacio Sanmillan (@ulexec)
- WebKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved bounds checks.
WebKit Bugzilla: 255350
CVE-2023-32409: Clement Lecigne of Google's Threat Analysis Group and Donncha O Cearbhaill of Amnesty International’s Security Lab
- WebKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
Description: An out-of-bounds read was addressed with improved input validation.
WebKit Bugzilla: 254930
CVE-2023-28204: an anonymous researcher
* This issue was first addressed in Rapid Security Response iOS 16.4.1 (a) and iPadOS 16.4.1 (a).
- WebKit
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 254840
CVE-2023-32373: an anonymous researcher
* This issue was first addressed in Rapid Security Response iOS 16.4.1 (a) and iPadOS 16.4.1 (a).
- Wi-Fi
Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to disclose kernel memory
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2023-32389: Pan ZhenPeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
Additional recognition
- Accounts
We would like to acknowledge Sergii Kryvoblotskyi of MacPaw Inc. for their assistance.
- CloudKit
We would like to acknowledge Iconic for their assistance.
- libxml2
We would like to acknowledge OSS-Fuzz, and Ned Williamson of Google Project Zero for their assistance.
- Reminders
We would like to acknowledge Kirin (@Pwnrin) for their assistance.
- Security
We would like to acknowledge Brandon Toms for their assistance.
- Share Sheet
We would like to acknowledge Kirin (@Pwnrin) for their assistance.
- Wallet
We would like to acknowledge James Duffy (mangoSecure) for their assistance.
- Wi-Fi Connectivity
We would like to acknowledge an anonymous researcher for their assistance.
記事執筆:memn0ck
■関連リンク
・エスマックス(S-MAX)
・エスマックス(S-MAX) smaxjp on Twitter
・S-MAX - Facebookページ
・iOS 16 関連記事一覧 - S-MAX
・iPadOS 16 関連記事一覧 - S-MAX
・iOS 16 のアップデートについて - Apple サポート (日本)
・iPadOS 16 のアップデートについて - Apple サポート (日本)
・iOS 16.5 および iPadOS 16.5 のセキュリティコンテンツについて - Apple サポート (日本)
・Apple セキュリティアップデート - Apple サポート