First published: Mon Mar 14 2022(Updated: )
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.
Credit: Will Blaschko Team Quasko product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <15.4 | |
Apple iPhone OS | <15.4 | |
Apple iOS | <15.4 | 15.4 |
Apple iPadOS | <15.4 | 15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22598 is a vulnerability that allows an app to learn information about the current camera view before being granted camera access on Apple devices running iOS or iPadOS versions up to and excluding 15.4.
CVE-2022-22598 affects Apple iOS and iPadOS versions up to and excluding 15.4.
The severity of CVE-2022-22598 is low with a CVSS score of 3.3.
CVE-2022-22598 was fixed in iOS 15.4 and iPadOS 15.4 through improved logic for app access to camera metadata.