Unrated severityNVD Advisory· Published Dec 15, 2022· Updated Apr 21, 2025
CVE-2022-42855
CVE-2022-42855
Description
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<16.2+ 1 more
- (no CPE)range: <16.2
- (no CPE)range: unspecified
- Range: <15.7.2 || <16.2
- Range: <13.1
- Range: <12.6.2
- Range: <15.7.2 || <16.2
Patches
Vulnerability mechanics
References
12- seclists.org/fulldisclosure/2022/Dec/20mitremailing-list
- seclists.org/fulldisclosure/2022/Dec/21mitremailing-list
- seclists.org/fulldisclosure/2022/Dec/23mitremailing-list
- seclists.org/fulldisclosure/2022/Dec/24mitremailing-list
- seclists.org/fulldisclosure/2022/Dec/26mitremailing-list
- packetstormsecurity.com/files/170518/libCoreEntitlements-CEContextQuery-Arbitrary-Entitlement-Returns.htmlmitre
- support.apple.com/en-us/HT213530mitre
- support.apple.com/en-us/HT213531mitre
- support.apple.com/en-us/HT213532mitre
- support.apple.com/en-us/HT213533mitre
- support.apple.com/en-us/HT213535mitre
- support.apple.com/kb/HT213536mitre
News mentions
0No linked articles in our index yet.