CVE-2022-22643
published 2022-03-18CVE-2022-22643: This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.23%
65.8th percentile
This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a FaceTime call without knowing that they have done so.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios_15.4_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.4 | 15.4 |
| apple | ipados | < 15.4 | 15.4 |
| apple | iphone_os | < 15.4 | 15.4 |
| apple | macos | >= 12.0 < 12.3 | 12.3 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| apple | macos_ventura | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22643: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 7.5
CVE-2022-22643 [HIGH] CVE-2022-22643: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-22643
Component: FaceTime
Impact: A user may send audio and video in a FaceTime call without knowing that they have done so
Description: This issue was addressed with improved checks.
Apple
CVE-2022-22643: iOS 16
vendor_apple·2022-09-12·CVSS 7.5
CVE-2022-22643 [HIGH] CVE-2022-22643: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-22643
Component: FaceTime
Impact: A user may send audio and video in a FaceTime call without knowing that they have done so
Description: This issue was addressed with improved checks.
Apple
CVE-2022-22643: iOS 15.4 and iPadOS 15.4
vendor_apple·2022-03-14·CVSS 7.5
CVE-2022-22643 [HIGH] CVE-2022-22643: iOS 15.4 and iPadOS 15.4
Apple Security Update: About the security content of iOS 15.4 and iPadOS 15.4
Product: iOS 15.4 and iPadOS
Version: 15.4
CVE: CVE-2022-22643
Component: FaceTime
Impact: A user may send audio and video in a FaceTime call without knowing that they have done so
Description: This issue was addressed with improved checks.
Apple
CVE-2022-22643: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 7.5
CVE-2022-22643 [HIGH] CVE-2022-22643: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22643
Component: FaceTime
Impact: A user may send audio and video in a FaceTime call without knowing that they have done so
Description: This issue was addressed with improved checks.
VulDB
Apple iOS/iPadOS up to 15.3.1 FaceTime information disclosure (HT213182 / EUVD-2022-27788)
vuldb·2026-04-28·CVSS 7.5
CVE-2022-22643 [HIGH] Apple iOS/iPadOS up to 15.3.1 FaceTime information disclosure (HT213182 / EUVD-2022-27788)
A vulnerability was found in Apple iOS and iPadOS up to 15.3.1. It has been declared as problematic. This vulnerability affects unknown code of the component FaceTime. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2022-22643. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
VulDB
Apple macOS FaceTime information disclosure (HT213183 / EUVD-2022-27788)
vuldb·2026-04-28·CVSS 7.5
CVE-2022-22643 [HIGH] Apple macOS FaceTime information disclosure (HT213183 / EUVD-2022-27788)
A vulnerability, which was classified as problematic, has been found in Apple macOS. This affects an unknown function of the component FaceTime. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2022-22643. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-v42r-j3h2-xv87: This issue was addressed with improved checks
ghsa_unreviewed·2022-03-19
CVE-2022-22643 [HIGH] GHSA-v42r-j3h2-xv87: This issue was addressed with improved checks
This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a FaceTime call without knowing that they have done so.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-18
Published