CVE-2022-32833Insecure Storage of Sensitive Information in Apple IOS

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 46.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

CVEListV5apple/iosunspecified16
NVDapple/macos< 13.0
NVDapple/safari< 16.0
NVDapple/iphone_os< 16.0

🔴Vulnerability Details

2
CVEList
CVE-2022-32833: An issue existed with the file paths used to store website data2022-12-15
GHSA
GHSA-qg5p-r35g-xqfm: An issue existed with the file paths used to store website data2022-12-15

📋Vendor Advisories

3
Apple
CVE-2022-32833: macOS Ventura 132022-10-24
Apple
CVE-2022-32833: iOS 162022-09-12
Apple
CVE-2022-32833: Safari 162022-09-12
CVE-2022-32833 — Apple IOS vulnerability | cvebase