CERT-In Vulnerability Note
CIVN-2022-0476
Multiple vulnerabilities in Apple Products
Original Issue Date:December 16, 2022
Severity Rating: HIGH
Software Affected
- Apple tvOS versions prior to 16.2
- Apple WatchOS versions prior to 9.2
Overview
Multiple vulnerabilities have been reported in Apple products which could allow an attacker to bypass Privacy preferences, execute kernel code, execute arbitrary code, gain access to sensitive data, and spoof user interface on the targeted system.
Description
These vulnerabilities exist in Apple tvOS and watchOS products due to flaw in information Disclosure in Accounts , ImageIO and WebKit; kernel code execution in AppleAVD and Kernel ; bypass Privacy preferences in AppleMobileFileIntegrity; CoreServices; arbitrary code with kernel privileges in AVEVideoEncoder , IOHIDFamily , IOMobileFrameBuffer and Kernel; Arbitrary code execution in ImageIO, libxml2 and WebKit; unexpected app termination or arbitrary code execution in iTunes Store & libxml2; arbitrary entitlements in Preferences; UI spoofing in Safari; elevate privileges in Software Update; read sensitive location information in Weather; bypass Same Origin Policy in WebKit; and disclosure of process memory in WebKit .
Successful exploitation of these vulnerabilities could allow the attacker to information Disclosure, bypass Privacy preferences, execute kernel code, execute arbitrary code, gain access to sensitive data, and spoof user interface on the targeted system.
Solution
Apply appropriate software updates as mentioned in the Apple Security updates:
https://support.apple.com/en-us/HT213535
https://support.apple.com/en-us/HT213536
Vendor Information
Apple
https://support.apple.com/en-us/HT213535
https://support.apple.com/en-us/HT213536
References
Apple
https://support.apple.com/en-us/HT213535
https://support.apple.com/en-us/HT213536
CVE Name
CVE-2022-42843
CVE-2022-46694
CVE-2022-42865
CVE-2022-42859
CVE-2022-46693
CVE-2022-42864
CVE-2022-46690
CVE-2022-42837
CVE-2022-46689
CVE-2022-42842
CVE-2022-42845
CVE-2022-40303
CVE-2022-40304
CVE-2022-46695
CVE-2022-42849
CVE-2022-42866
CVE-2022-42867
CVE-2022-46691
CVE-2022-46692
CVE-2022-42852
CVE-2022-46696
CVE-2022-46700
CVE-2022-46698
CVE-2022-46699
CVE-2022-42863
CVE-2022-42848
CVE-2022-42851
CVE-2022-46701
CVE-2022-42855
CVE-2022-42856
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|