CVE-2022-46693

Severity
7.8HIGH
EPSS
0.3%
top 49.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5apple/icloud_for_windowsunspecified14.1
CVEListV5apple/tvosunspecified16.2+1
NVDapple/tvos< 16.2
NVDapple/macos< 13.1
NVDapple/icloud< 14.1

🔴Vulnerability Details

2
CVEList
CVE-2022-46693: An out-of-bounds write issue was addressed with improved input validation2022-12-15
GHSA
GHSA-qjg8-52hj-5hj8: An out-of-bounds write issue was addressed with improved input validation2022-12-15

📋Vendor Advisories

5
Apple
CVE-2022-46693: tvOS16.22022-12-13
Apple
CVE-2022-46693: iOS 16.2 and iPadOS 16.22022-12-13
Apple
CVE-2022-46693: macOS Ventura 13.12022-12-13
Apple
CVE-2022-46693: watchOS 9.22022-12-13
Apple
CVE-2022-46693: iCloud for Windows 14.12022-12-13
CVE-2022-46693 (HIGH CVSS 7.8) | An out-of-bounds write issue was ad | cvebase.io