CVE-2022-22666: Apple iPadOS

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. Processing a maliciously crafted image may lead to heap corruption.

Affected products

  • Apple iPadOS: before 15.4 (fixed in 15.4)
  • Apple iPhone OS: before 15.4 (fixed in 15.4)
  • Apple tvOS: before 15.4 (fixed in 15.4)
  • Apple watchOS: before 8.5 (fixed in 8.5)

Published 2022-03-18. Last modified 2026-06-17.