CVE-2022-22677Improper Resource Shutdown or Release in Apple Macos

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 57.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Latest updateNov 2

Description

A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages8 packages

CVEListV5apple/macosunspecified12.4+1
NVDapple/macos12.0.012.4
NVDapple/ipados< 15.5
NVDapple/iphone_os< 15.5

🔴Vulnerability Details

2
GHSA
GHSA-q4jh-7c38-fcx6: A logic issue in the handling of concurrent media was addressed with improved state handling2022-11-02
OSV
CVE-2022-22677: A logic issue in the handling of concurrent media was addressed with improved state handling2022-11-01

📋Vendor Advisories

5
Ubuntu
WebKitGTK vulnerabilities2022-07-18
Red Hat
webkitgtk: the video in a webRTC call may be interrupted if the audio capture gets interrupted2022-07-05
Apple
CVE-2022-22677: iOS 15.5 and iPadOS 15.52022-05-16
Apple
CVE-2022-22677: macOS Monterey 12.42022-05-16
Debian
CVE-2022-22677: webkit2gtk - A logic issue in the handling of concurrent media was addressed with improved st...2022