CVE-2022-22653: High severity apple ios and ipados vulnerability
Published Mar 14, 2022
·Updated
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4. A malicious website may be able to access information about the user and their devices.
Other sources
iTunes. A logic issue was addressed with improved restrictions.
Credit
Aymeric Chaib(CERT Banque de France)
Affected Software
4 affected componentsFixes available
Apple iOS and iPadOS<15.4
15.4
Apple iOS, iPadOS, and macOS<15.4
15.4
Apple iOS, iPadOS, and macOS<15.4
iPhone OS<15.4
Event History
Mar 18, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-22633
- CVE-2022-22666
- CVE-2022-22634
- CVE-2022-22635
- CVE-2022-22636
- CVE-2022-22652
- CVE-2022-22598
- CVE-2022-22663
- CVE-2022-22642
- CVE-2022-22643
- CVE-2022-22667
- CVE-2022-22611
- CVE-2022-22612
- CVE-2022-22641
- CVE-2022-22653
- CVE-2022-22596
- CVE-2022-22640
- CVE-2022-22613
- CVE-2022-22614
- CVE-2022-22615
- CVE-2022-22632
- CVE-2022-22638
- CVE-2021-30946
- CVE-2021-36976
- CVE-2022-21658
- CVE-2022-22622
- CVE-2022-22670
- CVE-2022-22672
- CVE-2022-22659
- CVE-2022-22618
- CVE-2022-22609
- CVE-2022-22655
- CVE-2022-22600
- CVE-2022-22599
- CVE-2022-22639
- CVE-2022-22621
- CVE-2022-22671
- CVE-2022-22662
- CVE-2022-22610
- CVE-2022-22624
- CVE-2022-22628
- CVE-2022-22629
- CVE-2022-22637
- CVE-2022-22668
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22653.
2
What is the severity of CVE-2022-22653?
The severity of CVE-2022-22653 is high with a severity value of 7.5.
3
Which Apple software versions are affected by CVE-2022-22653?
iOS 15.4, iPadOS 15.4, Apple iPadOS up to version 15.4, and Apple iPhone OS up to version 15.4 are affected by CVE-2022-22653.
4
How was CVE-2022-22653 fixed?
CVE-2022-22653 was fixed in iOS 15.4 and iPadOS 15.4.
5
What is the potential impact of CVE-2022-22653?
A malicious website may be able to access information about the user and their devices.