High severity7.1NVD Advisory· Published Dec 15, 2022· Updated Jun 17, 2026
CVE-2022-42855
CVE-2022-42855
Description
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <15.7.2
- (no CPE)range: <=15.7.2, <=16.2
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: <12.6.2
- cpe:2.3:o:apple:macos:13.0:*:*:*:*:*:*:*
- (no CPE)range: <=12.6.2, <=13.1
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <16.2
- (no CPE)range: <16.2
- (no CPE)range: unspecified
- Range: <=15.7.2, <=16.2
Patches
Vulnerability mechanics
References
12- packetstormsecurity.com/files/170518/libCoreEntitlements-CEContextQuery-Arbitrary-Entitlement-Returns.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/Dec/20nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Dec/21nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Dec/23nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Dec/24nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Dec/26nvdMailing ListThird Party Advisory
- support.apple.com/en-us/HT213530nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213531nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213532nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213533nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213535nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT213536nvd
News mentions
0No linked articles in our index yet.