First published: Mon Oct 24 2022(Updated: )
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to bypass certain Privacy preferences
Credit: Mickey Jin @patch1t Csaba Fitzl @theevilbit Offensive SecurityAnonymous Trend Micro Zero Day InitiativeABC Research s.r.o. Jonathan Zhang Open Computing FacilityGuilherme Rambo Best Buddy AppsBistrit Dahal Asahi Lina @LinaAsahi Willy R. Vasquez The University of Texas at AustinPeter Pan ZhenPeng STAR LabsTingting Yin Tsinghua UniversityTommy Muir @Muirey03 Tim Michaud @TimGMichaud MoveworksXinru Chi Pangu LabJohn Aakerblom @jaakerblom Ian Beer Google Project ZeroZweig Kunlun Laban anonymous researcher Xingwei Lin @xwlin_roy Ant Security LightYinyi Wu Ant Security LightIES Red Team ByteDanceMir Masood Ali Illinois at ChicagoPhD student Illinois at ChicagoUniversity Illinois at ChicagoMS student Illinois at ChicagoStony Brook University; Mohammad Ghasemisharif Illinois at ChicagoPhD Candidate Illinois at ChicagoAssociate Professor Illinois at ChicagoStony Brook University; Jason Polakis Illinois at ChicagoJustin Bui @slyd0g SnowflakeCristian Dinca Tudor Vianu National High School of Computer Science ofFrancisco Alonso @revskills Jihwan Kim @gPayl0ad Dohyun Lee @l33d0hyun Dohyun Lee @l33d0hyun SSD LabsAbdulrahman Alqabandi Microsoft Browser Vulnerability ResearchRyan Shin IAAI SecLab at Korea UniversityDohyun Lee @l33d0hyun DNSLab at Korea UniversityYonghwi Jin at Theori @jinmo123 Trend Micro Zero Day InitiativeWonyoung Jung @nonetype_pwn KAIST Hacking LabDr Hideaki Goto Tohoku UniversityJapan Evgeny Legerov Mohamed Ghannam @_simo36 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <16.1 | 16.1 |
Apple iOS, iPadOS, and watchOS | <16 | 16 |
Apple iOS, iPadOS, and watchOS | <16.0 | |
iStyle @cosme iPhone OS | <16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-46715 is a vulnerability in NetworkExtension with a logic issue that has been addressed with improved checks.
CVE-2022-46715 affects Apple iOS versions up to but not including 16.1 and Apple iPadOS versions up to but not including 16.
To fix CVE-2022-46715, update your Apple device to iOS 16.1 or later, or iPadOS 16 or later.
You can find more information about CVE-2022-46715 on the official Apple support website at: https://support.apple.com/en-us/HT213489