Improper access control in Apple iOS and iPadOS - CVE-2022-46717
Published: March 20, 2023
Vulnerability identifier: #VU73797
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46717
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions within the Accessibility feature. An attacker with physical access to the locked Apple Watch may be able to view user photos via accessibility features.
Affected software
Apple iOS
iPadOS
watchOS
iPadOS
watchOS
How to mitigate CVE-2022-46717
Install updates from vendor's website.
Apple iOS - update to 16.2 20C65
iPadOS - update to 16.2 20C65
watchOS - update to 9.2 20S361
iPadOS - update to 16.2 20C65
watchOS - update to 9.2 20S361