CVE-2022-46695

MEDIUM EXPLOITED

Apple TV OS <16.2- iPad OS <16.2 - Spoofing

Title source: llm
STIX 2.1

Description

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.

Scores

CVSS v3 6.5
EPSS 0.0076
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2022-12-13
CWE
CWE-1021
Status published
Products (5)
apple/ipados < 15.7.2
apple/iphone_os < 15.7.2
apple/macos < 13.1
apple/tvos < 16.2
apple/watchos < 9.2
Published Dec 15, 2022
Tracked Since Feb 18, 2026