CVE-2022-46725: Input Validation
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
Other sources
Accessibility. A logic issue was addressed with improved restrictions.
— Apple
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accounts. This issue was addressed with improved data protection.
— Apple
AMD. A memory corruption issue was addressed with improved input validation.
— Apple
AMD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42843
- CVE-2022-42858
- CVE-2022-42847
- CVE-2022-42865
- CVE-2022-42854
- CVE-2022-42853
- CVE-2022-42859
- CVE-2022-35252
- CVE-2022-32942
- CVE-2022-46720
- CVE-2022-46710
- CVE-2022-46693
- CVE-2022-42864
- CVE-2022-46690
- CVE-2022-46697
- CVE-2022-42837
- CVE-2022-46689
- CVE-2022-46701
- CVE-2022-42842
- CVE-2022-42861
- CVE-2022-42845
- CVE-2022-48618
- CVE-2022-42839
- CVE-2022-46716
- CVE-2022-46704
- CVE-2022-32943
- CVE-2022-42840
- CVE-2022-42855
- CVE-2022-42862
- CVE-2022-24836
- CVE-2022-29181
- CVE-2022-46695
- CVE-2022-46718
- CVE-2022-46703
- CVE-2022-42866
- CVE-2022-32919
- CVE-2022-46725
- CVE-2022-46705
- CVE-2022-42867
- CVE-2022-46691
- CVE-2022-46692
- CVE-2022-42852
- CVE-2022-46696
- CVE-2022-46700
- CVE-2022-46698
- CVE-2022-46699
- CVE-2022-42863
- CVE-2022-42856
- CVE-2022-42841
- CVE-2022-46717
- CVE-2022-46694
- CVE-2022-42848
- CVE-2022-46702
- CVE-2022-42850
- CVE-2022-42846
- CVE-2022-42851
- CVE-2022-43454
- CVE-2022-42844
- CVE-2022-48610
- CVE-2022-42849
- CVE-2023-23541
- CVE-2023-42830
- CVE-2023-23540
- CVE-2023-27959
- CVE-2023-27970
- CVE-2023-23532
- CVE-2023-23527
- CVE-2023-27931
- CVE-2023-27961
- CVE-2023-23543
- CVE-2023-23494
- CVE-2023-27955
- CVE-2023-23528
- CVE-2023-28181
- CVE-2023-40398
- CVE-2023-28195
- CVE-2023-23537
- CVE-2023-32366
- CVE-2023-27956
- CVE-2023-27937
- CVE-2023-23526
- CVE-2023-27928
- CVE-2023-23535
- CVE-2023-27929
- CVE-2023-42862
- CVE-2023-42865
- CVE-2023-28187
- CVE-2023-28185
- CVE-2023-32424
- CVE-2023-27969
- CVE-2023-27933
- CVE-2023-23536
- CVE-2023-27943
- CVE-2023-23525
- CVE-2023-41075
- CVE-2022-46724
- CVE-2023-28182
- CVE-2023-23523
- CVE-2023-27942
- CVE-2023-28194
- CVE-2023-28178
- CVE-2023-27963
- CVE-2023-28188
- CVE-2023-32370
- CVE-2023-28198
- CVE-2023-32435
- CVE-2023-27932
- CVE-2023-27954
- CVE-2014-1745
- CVE-2023-32358
- CVE-2023-28201
Frequently Asked Questions
What is CVE-2022-46725?
CVE-2022-46725 is a spoofing issue that existed in the handling of URLs in WebKit, which has been addressed with improved input validation.
What is the severity of CVE-2022-46725?
CVE-2022-46725 has a severity value of 4.3, which is considered medium.
How does CVE-2022-46725 affect iOS and iPadOS?
CVE-2022-46725 affects iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.
How can I fix CVE-2022-46725?
To fix CVE-2022-46725, update your iOS or iPadOS to version 16.4 or newer.
Where can I find more information about CVE-2022-46725?
You can find more information about CVE-2022-46725 on the Apple support website: https://support.apple.com/en-us/HT213676