First published: Mon Mar 14 2022(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
Credit: product-security@apple.com hjy79425575 hjy79425575 hjy79425575 hjy79425575 hjy79425575 hjy79425575 hjy79425575 hjy79425575
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Xcode | <13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22602 is an out-of-bounds read vulnerability in otool, a tool in Apple Xcode.
CVE-2022-22602 can lead to an out-of-bounds read in otool, potentially resulting in information disclosure or a crash of the application.
The severity of CVE-2022-22602 is dependent on the specific use case, but it is generally rated as high due to the potential for information disclosure or application crashes.
To fix the CVE-2022-22602 vulnerability, update your Apple Xcode installation to version 13.3 or higher, which includes improved bounds checking in otool.
You can find more information about CVE-2022-22602 on the Apple support website: https://support.apple.com/en-us/HT213189