VulnerabilityModified
CVE-2022-22670
A malicious application may be able to identify what other applications a user has installed.
LOW 3.3EPSS 0.69%
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Affected
- apple/ipados · apple/iphone os · apple/tvos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT213182Vendor Advisory
- https://support.apple.com/en-us/HT213186Vendor Advisory
- https://support.apple.com/en-us/HT213193Vendor Advisory
- https://support.apple.com/en-us/HT213182Vendor Advisory
- https://support.apple.com/en-us/HT213186Vendor Advisory
- https://support.apple.com/en-us/HT213193Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.