First published: Tue Dec 13 2022(Updated: )
iTunes Store. An issue existed in the parsing of URLs. This issue was addressed with improved input validation.
Credit: Weijia Dai @dwj1210 Momo SecurityWeijia Dai @dwj1210 Momo SecurityWeijia Dai @dwj1210 Momo SecurityWeijia Dai @dwj1210 Momo Securityan anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | >=15.0<15.7.2 | |
Apple iPadOS | >=16.0<16.2 | |
Apple iPhone OS | >=15.0<15.7.2 | |
Apple iPhone OS | >=16.0<16.2 | |
Apple macOS | =13.0 | |
Apple watchOS | <9.2 | |
Apple tvOS | <16.2 | 16.2 |
<13.1 | 13.1 | |
<9.2 | 9.2 | |
Apple iOS | <16.2 | 16.2 |
Apple iPadOS | <16.2 | 16.2 |
Apple iOS | <15.7.2 | 15.7.2 |
Apple iPadOS | <15.7.2 | 15.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this iTunes Store issue is CVE-2022-42837.
The affected software includes Apple iOS (up to version 16.2), Apple iPadOS (up to version 16.2), Apple macOS Ventura (up to version 13.1), Apple iOS (up to version 15.7.2), Apple iPadOS (up to version 15.7.2), Apple tvOS (up to version 16.2), and Apple watchOS (up to version 9.2).
The severity of CVE-2022-42837 has not been specified.
To fix the iTunes Store vulnerability CVE-2022-42837, update your affected software to the latest version available.
You can find more information about CVE-2022-42837 on the Apple support website.