CVE-2022-42838
published 2023-02-27CVE-2022-42838: An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue…
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.22%
13.2th percentile
An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 13.0 | 13.0 |
| apple | macos | >= unspecified < 13 | 13 |
| apple | macos_ventura | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-42838: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 3.3
CVE-2022-42838 [LOW] CVE-2022-42838: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-42838
Component: CoreMedia
Impact: A camera extension may be able to continue receiving video after the app which activated was closed
Description: An issue with app access to camera data was addressed with improved logic.
GHSA
GHSA-x34g-7f63-j8qp: An issue with app access to camera data was addressed with improved logic
ghsa_unreviewed·2023-02-27
CVE-2022-42838 [LOW] CWE-672 GHSA-x34g-7f63-j8qp: An issue with app access to camera data was addressed with improved logic
An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-27
Published