QID 610455

Date Published: 2022-12-14

QID 610455: Apple iOS 15.7.2 and iPadOS 15.7.2 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
An out-of-bounds write issue was addressed with improved input validation. CVE-2022-46694
A logic issue was addressed with improved checks. CVE-2022-42848
This issue was addressed with improved checks. CVE-2022-42861
The issue was addressed with improved memory handling. CVE-2022-42846
A race condition was addressed with improved state handling. CVE-2022-42864
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. CVE-2022-42837
A race condition was addressed with additional validation. CVE-2022-46689
An integer overflow was addressed through improved input validation. CVE-2022-40303
This issue was addressed with improved checks. CVE-2022-40304
The issue was addressed with improved memory handling. CVE-2022-42840
A logic issue was addressed with improved state management. CVE-2022-42855
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. CVE-2022-46695
A memory consumption issue was addressed with improved memory handling. WebKit Bugzilla
The issue was addressed with improved memory handling. CVE-2022-42852
A logic issue was addressed with improved state management. WebKit Bugzilla
A memory corruption issue was addressed with improved input validation. WebKit Bugzilla
A type confusion issue was addressed with improved state handling. WebKit Bugzilla

Affected Devices
iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213531 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213531 iOS URL Logo support.apple.com/en-in/HT213531