CVE-2022-46694

high

Description

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.

References

https://support.apple.com/en-us/HT213535

https://support.apple.com/en-us/HT213531

https://support.apple.com/en-us/HT213536

https://support.apple.com/en-us/HT213530

http://seclists.org/fulldisclosure/2022/Dec/27

http://seclists.org/fulldisclosure/2022/Dec/26

http://seclists.org/fulldisclosure/2022/Dec/21

http://seclists.org/fulldisclosure/2022/Dec/20

Details

Source: Mitre, NVD

Published: 2022-12-15

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High