CVE-2022-32893
published 2022-08-24CVE-2022-32893: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari…
PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-09-08
Exploited in the wild
EPSS
9.79%
95.0th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios_15.6.1_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.6 | 15.6 |
| apple | ipados | < 15.6.1 | 15.6.1 |
| apple | iphone_os | < 15.6.1 | 15.6.1 |
| apple | macos | >= 12.0 < 12.5.1 | 12.5.1 |
| apple | macos | >= unspecified < 12.5 | 12.5 |
| apple | macos_monterey | — | — |
| apple | safari | < 15.6.1 | 15.6.1 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 15.6 | 15.6 |
| apple | watchos_9 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | webkit2gtk | < webkit2gtk 2.36.7-1 (bookworm) | webkit2gtk 2.36.7-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.36.7-1 (bookworm) | webkit2gtk 2.36.7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| webkitgtk | webkitgtk | < 2.36.7 | 2.36.7 |
| wpewebkit | wpe_webkit | < 2.36.7 | 2.36.7 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is in the WebKit component; trigger vector is processing maliciously crafted web content delivered via a browser or web view, leading to an out-of-bounds write and arbitrary code execution. ↗
- →On Linux/Red Hat environments, the affected packages are webkitgtk (RHEL 6) and webkitgtk3 (RHEL 7); monitor for exploitation of these packages via network-delivered web content. ↗
- ·CVE-2022-32893 was actively exploited in the wild at time of disclosure; patched versions are iOS 15.6.1/iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1, and iOS 12.5.6. Unpatched devices remain at risk. ↗
- ·RHEL 6 and RHEL 7 webkitgtk packages are out of support scope for this flaw and will not receive patches; organizations running these versions should consider mitigating controls. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qjpw-c5xf-g33j: An out-of-bounds write issue was addressed with improved bounds checking
ghsa_unreviewed·2022-08-25
CVE-2022-32893 [HIGH] CWE-787 GHSA-qjpw-c5xf-g33j: An out-of-bounds write issue was addressed with improved bounds checking
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
OSV
CVE-2022-32893: An out-of-bounds write issue was addressed with improved bounds checking
osv·2022-08-24·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: An out-of-bounds write issue was addressed with improved bounds checking
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
VulnCheck
Apple iOS and macOS Out-of-Bounds Write Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-32893 [HIGH] CWE-20 Apple iOS and macOS Out-of-Bounds Write Vulnerability
Apple iOS and macOS Out-of-Bounds Write Vulnerability
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.
Affected: Apple iOS and macOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/kb/HT213412; https://support.apple.com/kb/HT213413; https://support.apple.com/kb/HT213414; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://support.apple.com/kb/HT213428; https://support.apple.com/kb/HT213486; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Repor
Ubuntu
WebKitGTK vulnerability
vendor_ubuntu·2022-09-14
CVE-2022-32893 WebKitGTK vulnerability
Title: WebKitGTK vulnerability
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Apple
CVE-2022-32893: watchOS 9
vendor_apple·2022-09-12·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: watchOS 9
Apple Security Update: About the security content of watchOS 9
Product: watchOS 9
CVE: CVE-2022-32893
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2022-32893: iOS 12.5.6
vendor_apple·2022-08-31·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: iOS 12.5.6
Apple Security Update: About the security content of iOS 12.5.6
Product: iOS
Version: 12.5.6
CVE: CVE-2022-32893
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Red Hat
webkitgtk: processing maliciously crafted web content may lead to arbitrary code execution
vendor_redhat·2022-08-25·CVSS 8.8
CVE-2022-32893 [HIGH] CWE-787 webkitgtk: processing maliciously crafted web content may lead to arbitrary code execution
webkitgtk: processing maliciously crafted web content may lead to arbitrary code execution
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A flaw was found in webkitgtk. The vulnerability occurs due to improper input validation, leading to an out-of-bounds write. This flaw allows an attacker with network access to pass specially crafted web content files, causing arbitrary code execution.
Statement: Since Red Hat Enterprise Linux 6 and 7 are Out-of-Support-Scope for Low/Moderate flaws, the issue is not currently plan
Apple
CVE-2022-32893: Safari 15.6.1
vendor_apple·2022-08-18·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: Safari 15.6.1
Apple Security Update: About the security content of Safari 15.6.1
Product: Safari
Version: 15.6.1
CVE: CVE-2022-32893
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CISA
Apple iOS and macOS Out-of-Bounds Write Vulnerability
cisa·2022-08-18·CVSS 8.8
CVE-2022-32893 [HIGH] CWE-20 Apple iOS and macOS Out-of-Bounds Write Vulnerability
Vulnerability: Apple iOS and macOS Out-of-Bounds Write Vulnerability
Affected: Apple iOS and macOS
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.
Required Action: Apply updates per vendor instructions.
Notes: https://support.apple.com/en-gb/HT213412, https://support.apple.com/en-gb/HT213413; https://nvd.nist.gov/vuln/detail/CVE-2022-32893
Remediation Due Date: 2022-09-08
Apple
CVE-2022-32893: iOS 15.6.1 and iPadOS 15.6.1
vendor_apple·2022-08-17·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: iOS 15.6.1 and iPadOS 15.6.1
Apple Security Update: About the security content of iOS 15.6.1 and iPadOS 15.6.1
Product: iOS 15.6.1 and iPadOS
Version: 15.6.1
CVE: CVE-2022-32893
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2022-32893: macOS Monterey 12.5.1
vendor_apple·2022-08-17·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: macOS Monterey 12.5.1
Apple Security Update: About the security content of macOS Monterey 12.5.1
Product: macOS Monterey
Version: 12.5.1
CVE: CVE-2022-32893
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Debian
CVE-2022-32893: webkit2gtk - An out-of-bounds write issue was addressed with improved bounds checking. This i...
vendor_debian·2022·CVSS 8.8
CVE-2022-32893 [HIGH] CVE-2022-32893: webkit2gtk - An out-of-bounds write issue was addressed with improved bounds checking. This i...
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Scope: local
bookworm: resolved (fixed in 2.36.7-1)
bullseye: resolved (fixed in 2.36.7-1~deb11u1)
forky: resolved (fixed in 2.36.7-1)
sid: resolved (fixed in 2.36.7-1)
trixie: resolved (fixed in 2.36.7-1)
No detection rules found.
No public exploits indexed.
Qualys
September 2022 Patch Tuesday | Microsoft Releases 63 Vulnerabilities With 5 Critical, Plus 16 Microsoft Edge (Chromium-Based); Adobe Releases 7 Advisories, 63 Vulnerabilities With 35 Critical.
blogs_qualys·2022-09-13·CVSS 5.6
[MEDIUM] September 2022 Patch Tuesday | Microsoft Releases 63 Vulnerabilities With 5 Critical, Plus 16 Microsoft Edge (Chromium-Based); Adobe Releases 7 Advisories, 63 Vulnerabilities With 35 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The September 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Zero-Day Vulnerabilities Addressed
Microsoft Important Vulnerability Highlights
Microsoft Edge | Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Protection High-Rated Advisories from August to September 2022 Patch Tuesday Advisory
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Evaluate Vendor-Suggested Workarounds With Policy Compliance
Qualys This Month in Vulnerabilities and Patches Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
NEW & NOTEWORTHY
Qualys
September 2022 Patch Tuesday | Microsoft Releases 63 Vulnerabilities With 5 Critical, Plus 16 Microsoft Edge (Chromium-Based); Adobe Releases 7 Advisories, 63 Vulnerabilities With 35 Critical. | Qualy
blogs_qualys·2022-09-13·CVSS 5.6
[MEDIUM] September 2022 Patch Tuesday | Microsoft Releases 63 Vulnerabilities With 5 Critical, Plus 16 Microsoft Edge (Chromium-Based); Adobe Releases 7 Advisories, 63 Vulnerabilities With 35 Critical. | Qualy
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The September 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Zero-Day Vulnerabilities Addressed
- Microsoft Important Vulnerability Highlights
- Microsoft Edge | Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Protection High-Rated Advisories from August to September 2022 Patch Tuesday Advisory
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Evaluate Vendor-Suggested Workarounds With Policy Compliance
- Qualys This Month in Vulnerabilities and Patches Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
-
Checkpoint
22th August – Threat Intelligence Report
blogs_checkpoint·2022-08-22
CVE-2022-32893 22th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22th August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
South Staffordshire Water, UK’s largest water company supplying 330M liters of drinking water to 1.6M consumers daily, has been a victim of ransomware attack launched by Cl0p, a Russian-speaking ransomware gang. The group caused disruption of the company’s IT systems, allowing them access to more than 5TB of data including
http://seclists.org/fulldisclosure/2022/Aug/16http://seclists.org/fulldisclosure/2022/Oct/49http://www.openwall.com/lists/oss-security/2022/08/25/5http://www.openwall.com/lists/oss-security/2022/08/26/2http://www.openwall.com/lists/oss-security/2022/08/29/1http://www.openwall.com/lists/oss-security/2022/08/29/2http://www.openwall.com/lists/oss-security/2022/09/02/10http://www.openwall.com/lists/oss-security/2022/09/13/1https://lists.debian.org/debian-lts-announce/2022/08/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKJGV2EXVMYQW3OAJNI4WUTKKVMD2YYK/https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213412https://support.apple.com/en-us/HT213413https://support.apple.com/en-us/HT213414https://www.debian.org/security/2022/dsa-5219https://www.debian.org/security/2022/dsa-5220http://seclists.org/fulldisclosure/2022/Aug/16http://seclists.org/fulldisclosure/2022/Oct/49http://www.openwall.com/lists/oss-security/2022/08/25/5http://www.openwall.com/lists/oss-security/2022/08/26/2http://www.openwall.com/lists/oss-security/2022/08/29/1http://www.openwall.com/lists/oss-security/2022/08/29/2http://www.openwall.com/lists/oss-security/2022/09/02/10http://www.openwall.com/lists/oss-security/2022/09/13/1https://lists.debian.org/debian-lts-announce/2022/08/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKJGV2EXVMYQW3OAJNI4WUTKKVMD2YYK/https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213412https://support.apple.com/en-us/HT213413https://support.apple.com/en-us/HT213414https://www.debian.org/security/2022/dsa-5219https://www.debian.org/security/2022/dsa-5220https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-32893
2022-08-24
Published
2022-08-18
Added to CISA KEV
Exploited in the wild