2022 macOS Calendar vulnerability (CVE-2022-46723) allowed data access through malicious invites, addressed by Apple with multiple updates.

A zero-click vulnerability (CVE-2022-46723) in macOS Calendar was discovered in 2022 by researcher Mikko Kenttala. It allowed attackers to access sensitive data, including iCloud Photos, through malicious calendar invites. The flaw enabled file manipulation within the Calendar app. Apple addressed this issue with multiple software updates from October 2022 to September 2023. Users are advised to keep software updated and limit app access to sensitive information.

September 13, 2024
3 Articles

Further Reading