CVE-2022-42848: Input Validation
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
Other sources
Accessibility. A logic issue was addressed with improved restrictions.
— Apple
Accounts. This issue was addressed with improved data protection.
— Apple
AppleAVD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
AppleMobileFileIntegrity. This issue was addressed by enabling hardened runtime.
— Apple
AVEVideoEncoder. A logic issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42843
- CVE-2022-46694
- CVE-2022-42865
- CVE-2022-42848
- CVE-2022-46693
- CVE-2022-42851
- CVE-2022-42864
- CVE-2022-46690
- CVE-2022-42837
- CVE-2022-46689
- CVE-2022-46701
- CVE-2022-42842
- CVE-2022-42845
- CVE-2022-48618
- CVE-2022-40303
- CVE-2022-40304
- CVE-2022-42855
- CVE-2022-46695
- CVE-2022-42849
- CVE-2022-42866
- CVE-2022-46705
- CVE-2022-42867
- CVE-2022-46691
- CVE-2022-46692
- CVE-2022-42852
- CVE-2022-46696
- CVE-2022-46700
- CVE-2022-46698
- CVE-2022-46699
- CVE-2022-42863
- CVE-2022-42856
- CVE-2022-43454
- CVE-2022-46717
- CVE-2022-42859
- CVE-2022-46720
- CVE-2022-46702
- CVE-2022-42850
- CVE-2022-42846
- CVE-2022-46710
- CVE-2022-42861
- CVE-2022-42844
- CVE-2022-48610
- CVE-2022-42839
- CVE-2022-46716
- CVE-2022-32943
- CVE-2022-42840
- CVE-2022-42862
- CVE-2022-46718
- CVE-2022-46703
- CVE-2022-32919
- CVE-2022-46725
- CVE-2023-23496
Frequently Asked Questions
What is CVE-2022-42848?
CVE-2022-42848 is a logic issue in AVEVideoEncoder that has been addressed with improved checks.
Which software is affected by CVE-2022-42848?
CVE-2022-42848 affects Apple iOS, iPadOS, and tvOS versions up to 16.2.
How can I fix CVE-2022-42848?
To fix CVE-2022-42848, update your Apple iOS, iPadOS, or tvOS to version 16.2 or higher.
Where can I find more information about CVE-2022-42848?
You can find more information about CVE-2022-42848 on Apple's support page: <a href='https://support.apple.com/en-us/HT213530'>https://support.apple.com/en-us/HT213530</a>