First published: Wed Jul 20 2022(Updated: )
A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing an image may lead to a denial-of-service.
Credit: Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit Yiğit Can YILMAZ @yilmazcanyigit product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Catalina | ||
Apple macOS Big Sur | <11.6.8 | 11.6.8 |
<12.5 | 12.5 | |
Apple iOS | <15.6 | 15.6 |
Apple iPadOS | <15.6 | 15.6 |
Apple iPadOS | <15.6 | |
Apple iPhone OS | <15.6 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-004 | |
Apple Mac OS X | =10.15.7-security_update_2021-005 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-security_update_2022-003 | |
Apple macOS | <10.15.7 | |
Apple macOS | >=11.0<11.6.8 | |
Apple macOS | >=12.0<12.5 | |
Apple macOS | =10.15.7 | |
Apple macOS | =10.15.7-security_update_2022-004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-32785 is a vulnerability in ImageIO that allows for a null pointer dereference.
CVE-2022-32785 affects Apple iOS up to version 15.6, Apple iPadOS up to version 15.6, Apple macOS Big Sur up to version 11.6.8, and Apple macOS Monterey up to version 12.5.
The severity of CVE-2022-32785 is not specified.
To fix CVE-2022-32785, it is recommended to update to the latest version of the affected software as indicated by Apple.
You can find more information about CVE-2022-32785 on the Apple support website.