Out-of-bounds read in macOS - CVE-2022-22579
Published: January 26, 2022 / Updated: February 16, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition in Model I/O when processing STL files. A remote attacker can create a specially crafted STL file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory or execute arbitrary code on the system.
Affected software
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2022-22579
iPadOS - update to 15.3 19D50
Apple iOS - update to 15.3 19D50
tvOS - update to 15.3 19K547