CVE-2022-46701 is a critical vulnerability affecting Apple's iOS, iPadOS, macOS, and tvOS that could allow arbitrary code execution with kernel privileges. This high-severity flaw, rated 7.8 CVSS, arises from insufficient bounds checks, enabling an attacker to compromise a device by connecting to a malicious NFS server. While no public exploits, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, the potential for complete system compromise underscores its importance. Apple addressed this issue in iOS 16.2, iPadOS 16.2, macOS Ventura 13.1, and tvOS 16.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0, < 16.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.1CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 16.2CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 13.1CPE match | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.