Out-of-bounds read in Apple iOS and iPadOS - CVE-2022-42851
Published: December 14, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in ImageIO when parsing TIFF files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and gain access to sensitive information.
Affected software
iPadOS
tvOS
How to mitigate CVE-2022-42851
iPadOS - update to 16.2 20C65
tvOS - update to 16.2 20K362