CVE-2022-32802: Input Validation
A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted file may lead to arbitrary code execution.
Other sources
AMD. A memory corruption issue was addressed with improved input validation.
— Apple
APFS. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. An integer overflow was addressed with improved input validation.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-32832
- CVE-2022-32788
- CVE-2022-32824
- CVE-2022-32826
- CVE-2022-32820
- CVE-2022-32825
- CVE-2022-32828
- CVE-2022-32839
- CVE-2022-32819
- CVE-2022-32793
- CVE-2022-32821
- CVE-2022-32849
- CVE-2022-32787
- CVE-2022-32841
- CVE-2022-32802
- CVE-2022-32830
- CVE-2022-48503
- CVE-2022-32813
- CVE-2022-32815
- CVE-2022-32817
- CVE-2022-32844
- CVE-2022-26981
- CVE-2022-32823
- CVE-2022-32814
- CVE-2022-32857
- CVE-2022-32863
- CVE-2022-32816
- CVE-2022-32792
- CVE-2022-32837
- CVE-2022-32847
- CVE-2022-42858
- CVE-2022-32880
- CVE-2022-42805
- CVE-2022-32948
- CVE-2022-32810
- CVE-2022-32840
- CVE-2022-32845
- CVE-2022-48578
- CVE-2022-32797
- CVE-2022-32851
- CVE-2022-32852
- CVE-2022-32853
- CVE-2022-32831
- CVE-2022-32910
- CVE-2022-32789
- CVE-2022-32805
- CVE-2022-32897
- CVE-2022-32785
- CVE-2022-32811
- CVE-2022-32812
- CVE-2022-32829
- CVE-2022-32786
- CVE-2022-32800
- CVE-2022-32838
- CVE-2022-32843
- CVE-2022-46708
- CVE-2022-32796
- CVE-2022-32842
- CVE-2022-32798
- CVE-2022-32799
- CVE-2022-32818
- CVE-2022-32807
- CVE-2022-32801
- CVE-2021-28544
- CVE-2022-24070
- CVE-2022-29046
- CVE-2022-29048
- CVE-2022-32834
- CVE-2022-32933
- CVE-2022-32885
- CVE-2022-32861
- CVE-2022-2294
- CVE-2022-32860
- CVE-2022-32848
- CVE-2022-32855
- CVE-2022-26768
- CVE-2022-32784
Frequently Asked Questions
What is CVE-2022-32802?
CVE-2022-32802 is a logic issue in ImageIO that has been addressed with improved checks.
How does CVE-2022-32802 affect Apple macOS Monterey?
CVE-2022-32802 affects Apple macOS Monterey versions up to but excluding 12.5.
How does CVE-2022-32802 affect Apple iOS?
CVE-2022-32802 affects Apple iOS versions up to but excluding 15.6.
How does CVE-2022-32802 affect Apple iPadOS?
CVE-2022-32802 affects Apple iPadOS versions up to but excluding 15.6.
How does CVE-2022-32802 affect Apple tvOS?
CVE-2022-32802 affects Apple tvOS versions up to but excluding 15.6.
How can I fix CVE-2022-32802?
To fix CVE-2022-32802, make sure to update your operating system to a version that includes the security patch. Check Apple's official support page for the specific updates for your device.