CVE-2022-32888Out-of-bounds Write in Apple Macos

CWE-787Out-of-bounds Write13 documents7 sources
Severity
8.8HIGHNVD
EPSS
0.8%
top 26.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Latest updateNov 17

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages16 packages

CVEListV5apple/macosunspecified13+3
NVDapple/macos11.011.7+1

🔴Vulnerability Details

2
GHSA
GHSA-c3gw-7267-x4wq: An out-of-bounds write issue was addressed with improved bounds checking2022-11-02
OSV
CVE-2022-32888: An out-of-bounds write issue was addressed with improved bounds checking2022-11-01

📋Vendor Advisories

10
Ubuntu
WebKitGTK vulnerabilities2022-11-17
Red Hat
webkitgtk: out-of-bounds write issue was addressed with improved bounds checking2022-10-31
Apple
CVE-2022-32888: macOS Ventura 132022-10-24
Apple
CVE-2022-32888: macOS Big Sur 11.72022-09-12
Apple
CVE-2022-32888: macOS Monterey 12.62022-09-12