cbcvebase.
CVE-2022-22599
published 2022-03-18

CVE-2022-22599: Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5…

PriorityP46low2.4CVSS 3.1
AVPACLPRNUINSUCLINAN
EPSS
0.29%
20.6th percentile
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.

Affected

13 ranges
VendorProductVersion rangeFixed in
appleios_15.4_and_ipados
appleios_and_ipados>= unspecified < 15.415.4
appleipados< 15.415.4
appleiphone_os< 15.415.4
applemacos< 11.6.511.6.5
applemacos>= 12.0.0 < 12.312.3
applemacos>= unspecified < 12.312.3
applemacos>= unspecified < 11.611.6
applemacos_big_sur
applemacos_monterey
applewatchos< 8.58.5
applewatchos
applewatchos>= unspecified < 8.58.5

CVSS provenance

nvdv3.12.4LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.