CVE-2022-22582
published 2023-02-27CVE-2022-22582: A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update…
PriorityP341medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
17.71%
96.8th percentile
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | macos | >= 11.0 < 11.6.5 | 11.6.5 |
| apple | macos | >= 12.0.0 < 12.3 | 12.3 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos | >= unspecified < 2022 | 2022 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-003_catalina | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22582: macOS Big Sur 11.6.5
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22582 [MEDIUM] CVE-2022-22582: macOS Big Sur 11.6.5
Apple Security Update: About the security content of macOS Big Sur 11.6.5
Product: macOS Big Sur
Version: 11.6.5
CVE: CVE-2022-22582
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22582: Security Update 2022-003 Catalina
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22582 [MEDIUM] CVE-2022-22582: Security Update 2022-003 Catalina
Apple Security Update: About the security content of Security Update 2022-003 Catalina
Product: Security Update 2022-003 Catalina
CVE: CVE-2022-22582
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22582: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22582 [MEDIUM] CVE-2022-22582: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22582
Component: Wi-Fi
Impact: A malicious application may be able to leak sensitive user information
Description: A logic issue was addressed with improved restrictions.
VulDB
Apple macOS xar symlink (HT213183 / EUVD-2022-27727)
vuldb·2026-04-28·CVSS 5.5
CVE-2022-22582 [MEDIUM] Apple macOS xar symlink (HT213183 / EUVD-2022-27727)
A vulnerability was found in Apple macOS and classified as problematic. This impacts an unknown function of the component xar. Executing a manipulation can lead to symlink following.
The identification of this vulnerability is CVE-2022-22582. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-4r4v-x4wj-59wx: A validation issue existed in the handling of symlinks
ghsa_unreviewed·2023-02-27
CVE-2022-22582 [MEDIUM] CWE-59 GHSA-4r4v-x4wj-59wx: A validation issue existed in the handling of symlinks
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-27
Published