Improper access control in Apple iOS and iPadOS - CVE-2022-46717

 

Improper access control in Apple iOS and iPadOS - CVE-2022-46717

Published: March 20, 2023


Vulnerability identifier: #VU73797
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46717
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions within the Accessibility feature. An attacker with physical access to the locked Apple Watch may be able to view user photos via accessibility features.


Affected software

Apple iOS
iPadOS
watchOS

How to mitigate CVE-2022-46717

Install updates from vendor's website.

Apple iOS - update to 16.2 20C65
iPadOS - update to 16.2 20C65
watchOS - update to 9.2 20S361

External References

Related Security Bulletins