First published: Tue Mar 08 2022(Updated: )
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.
Credit: Xingyu Jin GoogleXingyu Jin GoogleXingyu Jin GoogleXingyu Jin GoogleXingyu Jin Google product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.12.3 | 12.12.3 |
Apple macOS Monterey | <12.3 | 12.3 |
Apple watchOS | <8.5 | 8.5 |
Apple tvOS | <15.4 | 15.4 |
Apple iOS | <15.4 | 15.4 |
Apple iPadOS | <15.4 | 15.4 |
Apple Itunes Windows | <12.12.3 | |
Apple iPadOS | <15.4 | |
Apple iPhone OS | <15.4 | |
Apple macOS | >=12.0<12.3 | |
Apple tvOS | <15.4 | |
Apple watchOS | <8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2022-22612 is high, with a severity value of 7.8.
CVE-2022-22612 affects tvOS 15.4, iOS 15.4, iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, and macOS Monterey 12.3.
To fix CVE-2022-22612, update to the latest versions of the affected software: tvOS 15.4, iOS 15.4, iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, and macOS Monterey 12.3.
CVE-2022-22612 is a memory consumption issue in ImageIO that has been addressed with improved memory handling. It could allow heap corruption when processing a maliciously crafted image.
Yes, you can find references for CVE-2022-22612 at the following links: [Reference 1](https://support.apple.com/en-us/HT213182), [Reference 2](https://support.apple.com/en-us/HT213183), [Reference 3](https://support.apple.com/en-us/HT213186).