Out-of-Bounds Write Vulnerability in Apple Products
CVE-2022-46693

7.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
15 December 2022

Summary

An out-of-bounds write vulnerability has been identified in several Apple products, where improper input validation allows processing of maliciously crafted files. This can potentially result in arbitrary code execution, posing significant security risks to users. The issue has been rectified in updates for tvOS, iCloud for Windows, macOS Ventura, iOS, iPadOS, and watchOS, highlighting the importance of keeping systems updated for enhanced security.

Affected Version(s)

iCloud for Windows < 14.1

tvOS < 16.2

tvOS < 13.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.