QID 610456

Date Published: 2022-12-14

QID 610456: Apple iOS 16.2 and iPadOS 16.2 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
This issue was addressed with improved data protection. CVE-2022-42843
An out-of-bounds write issue was addressed with improved input validation. CVE-2022-46694
This issue was addressed by enabling hardened runtime. CVE-2022-42865
A logic issue was addressed with improved checks. CVE-2022-42848
Multiple issues were addressed by removing the vulnerable code. CVE-2022-42859
The issue was addressed with improved memory handling. CVE-2022-46702
The issue was addressed with improved memory handling. CVE-2022-42850
The issue was addressed with improved memory handling. CVE-2022-42846
An out-of-bounds write issue was addressed with improved input validation. CVE-2022-46693
The issue was addressed with improved memory handling. CVE-2022-42851
A race condition was addressed with improved state handling. CVE-2022-42864
An out-of-bounds write issue was addressed with improved input validation. CVE-2022-46690
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. CVE-2022-42837
A race condition was addressed with additional validation. CVE-2022-46689
The issue was addressed with improved bounds checks. CVE-2022-46701
The issue was addressed with improved memory handling. CVE-2022-42842
This issue was addressed with improved checks. CVE-2022-42861
The issue was addressed with improved memory handling. CVE-2022-42844
The issue was addressed with improved memory handling. CVE-2022-42845
The issue was addressed with improved bounds checks. CVE-2022-32943
The issue was addressed with improved memory handling. CVE-2022-42840
A logic issue was addressed with improved state management. CVE-2022-42855
This issue was addressed by removing the vulnerable code. CVE-2022-42862
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. CVE-2022-46695
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. CVE-2022-42849
The issue was addressed with improved handling of caches. CVE-2022-42866
A use after free issue was addressed with improved memory management. WebKit Bugzilla
A memory consumption issue was addressed with improved memory handling. WebKit Bugzilla
A logic issue was addressed with improved state management. WebKit Bugzilla
The issue was addressed with improved memory handling. CVE-2022-42852
A memory corruption issue was addressed with improved input validation. WebKit Bugzilla
A logic issue was addressed with improved checks. CVE-2022-46698
A memory corruption issue was addressed with improved state management. WebKit Bugzilla

Affected Devices
iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213530 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213530 iOS URL Logo support.apple.com/en-in/HT213530