CVE-2022-32849
published 2022-09-23CVE-2022-32849: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.24%
15.7th percentile
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.6_and_ipados | — | — |
| apple | ipados | < 15.6 | 15.6 |
| apple | iphone_os | < 15.6 | 15.6 |
| apple | mac_os_x | < 10.15.7 | 10.15.7 |
| apple | mac_os_x | — | — |
| apple | macos | >= 11.0 < 11.6.8 | 11.6.8 |
| apple | macos | >= 12.0 < 12.5 | 12.5 |
| apple | macos | >= unspecified < 12.5 | 12.5 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 2022 | 2022 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | macos_ventura | — | — |
| apple | security_update_2022-005_catalina | — | — |
| apple | tvos | < 15.6 | 15.6 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.6 | 15.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple macOS iCloud Photo Library information disclosure (HT213345 / EUVD-2022-35915)
vuldb·2026-06-02·CVSS 5.5
CVE-2022-32849 [MEDIUM] Apple macOS iCloud Photo Library information disclosure (HT213345 / EUVD-2022-35915)
A vulnerability, which was classified as problematic, has been found in Apple macOS. This affects an unknown part of the component iCloud Photo Library. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2022-32849. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.
VulDB
Apple tvOS up to 15.5.1 iCloud Photo Library information disclosure (HT213342 / EUVD-2022-35915)
vuldb·2026-06-02·CVSS 5.5
CVE-2022-32849 [MEDIUM] Apple tvOS up to 15.5.1 iCloud Photo Library information disclosure (HT213342 / EUVD-2022-35915)
A vulnerability was found in Apple tvOS up to 15.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component iCloud Photo Library. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2022-32849. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-79xc-f76g-hpg4: An information disclosure issue was addressed by removing the vulnerable code
ghsa_unreviewed·2022-09-25
CVE-2022-32849 [MEDIUM] CWE-200 GHSA-79xc-f76g-hpg4: An information disclosure issue was addressed by removing the vulnerable code
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.
Apple
CVE-2022-32849: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 5.5
CVE-2022-32849 [MEDIUM] CVE-2022-32849: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-32849
Component: Heimdal
Impact: A user may be able to cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Apple
CVE-2022-32849: macOS Monterey 12.5
vendor_apple·2022-07-20·CVSS 5.5
CVE-2022-32849 [MEDIUM] CVE-2022-32849: macOS Monterey 12.5
Apple Security Update: About the security content of macOS Monterey 12.5
Product: macOS Monterey
Version: 12.5
CVE: CVE-2022-32849
Component: GPU Drivers
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved validation.
Apple
CVE-2022-32849: Security Update 2022-005 Catalina
vendor_apple·2022-07-20·CVSS 5.5
CVE-2022-32849 [MEDIUM] CVE-2022-32849: Security Update 2022-005 Catalina
Apple Security Update: About the security content of Security Update 2022-005 Catalina
Product: Security Update 2022-005 Catalina
CVE: CVE-2022-32849
Component: Calendar
Impact: An app may be able to access user-sensitive data
Description: An information disclosure issue was addressed by removing the vulnerable code.
Apple
CVE-2022-32849: iOS 15.6 and iPadOS 15.6
vendor_apple·2022-07-20·CVSS 5.5
CVE-2022-32849 [MEDIUM] CVE-2022-32849: iOS 15.6 and iPadOS 15.6
Apple Security Update: About the security content of iOS 15.6 and iPadOS 15.6
Product: iOS 15.6 and iPadOS
Version: 15.6
CVE: CVE-2022-32849
Component: Home
Impact: A user may be able to view restricted content from the lock screen
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-32849: tvOS 15.6
vendor_apple·2022-07-20·CVSS 5.5
CVE-2022-32849 [MEDIUM] CVE-2022-32849: tvOS 15.6
Apple Security Update: About the security content of tvOS 15.6
Product: tvOS
Version: 15.6
CVE: CVE-2022-32849
Component: GPU Drivers
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved validation.
Apple
CVE-2022-32849: macOS Big Sur 11.6.8
vendor_apple·2022-07-20·CVSS 5.5
CVE-2022-32849 [MEDIUM] CVE-2022-32849: macOS Big Sur 11.6.8
Apple Security Update: About the security content of macOS Big Sur 11.6.8
Product: macOS Big Sur
Version: 11.6.8
CVE: CVE-2022-32849
Component: Calendar
Impact: An app may be able to access user-sensitive data
Description: An information disclosure issue was addressed by removing the vulnerable code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT213342https://support.apple.com/en-us/HT213343https://support.apple.com/en-us/HT213344https://support.apple.com/en-us/HT213345https://support.apple.com/en-us/HT213346https://support.apple.com/kb/HT213488https://support.apple.com/en-us/HT213342https://support.apple.com/en-us/HT213343https://support.apple.com/en-us/HT213344https://support.apple.com/en-us/HT213345https://support.apple.com/en-us/HT213346https://support.apple.com/kb/HT213488
2022-09-23
Published