First published: Tue Mar 08 2022(Updated: )
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.
Credit: Xingyu Jin Google product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <15.4 | 15.4 |
Apple iOS, iPadOS, and watchOS | <8.5 | 8.5 |
macOS | <12.3 | 12.3 |
iTunes | <12.12.3 | 12.12.3 |
Apple iOS and iPadOS | <15.4 | 15.4 |
Apple iOS, iPadOS, and macOS | <15.4 | 15.4 |
iTunes | <12.12.3 | |
Apple iOS, iPadOS, and macOS | <15.4 | |
iPhone OS | <15.4 | |
macOS | >=12.0<12.3 | |
tvOS | <15.4 | |
Apple iOS, iPadOS, and watchOS | <8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-22612 is high, with a severity value of 7.8.
CVE-2022-22612 affects tvOS 15.4, iOS 15.4, iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, and macOS Monterey 12.3.
To fix CVE-2022-22612, update to the latest versions of the affected software: tvOS 15.4, iOS 15.4, iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, and macOS Monterey 12.3.
CVE-2022-22612 is a memory consumption issue in ImageIO that has been addressed with improved memory handling. It could allow heap corruption when processing a maliciously crafted image.
Yes, you can find references for CVE-2022-22612 at the following links: [Reference 1](https://support.apple.com/en-us/HT213182), [Reference 2](https://support.apple.com/en-us/HT213183), [Reference 3](https://support.apple.com/en-us/HT213186).