First published: Tue Dec 13 2022(Updated: )
WebKit. A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
Credit: Hyeon Park @tree_segment Team ApplePIEHyeon Park @tree_segment Team ApplePIEHyeon Park @tree_segment Team ApplePIEHyeon Park @tree_segment Team ApplePIEHyeon Park @tree_segment Team ApplePIEHyeon Park @tree_segment Team ApplePIE product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Ventura | <13.1 | 13.1 |
Apple tvOS | <16.2 | 16.2 |
Apple iOS | <16.4 | 16.4 |
Apple iPadOS | <16.4 | 16.4 |
Apple Safari | <16.2 | 16.2 |
Apple Safari | <16.2 | |
Apple iPadOS | <15.7.2 | |
Apple iPadOS | >=16.0<16.2 | |
Apple iPhone OS | <15.7.2 | |
Apple iPhone OS | >=16.0<16.2 | |
Apple macOS | <13.1 | |
Apple tvOS | <16.2 | |
Apple watchOS | <9.2 | |
Apple iPadOS | <16.2 | |
Apple iPhone OS | <16.2 | |
<13.1 | 13.1 | |
<9.2 | 9.2 | |
Apple iOS | <15.7.2 | 15.7.2 |
Apple iPadOS | <15.7.2 | 15.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2022-46705 is a spoofing issue that existed in the handling of URLs in Apple products.
Apple iOS, iPadOS, macOS Ventura, Safari, watchOS, and tvOS versions up to and exclusive of 16.2, 13.1, 15.7.2, and 9.2 respectively are affected by CVE-2022-46705.
The severity of CVE-2022-46705 is not specified.
To fix CVE-2022-46705, update to the latest version of the affected Apple products, such as iOS, iPadOS, macOS Ventura, Safari, watchOS, and tvOS.
More information about CVE-2022-46705 can be found on the Apple support website.