CVE-2022-32895
published 2022-11-01CVE-2022-32895: A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file…
PriorityP419medium4.7CVSS 3.1
AVLACHPRNUIRSUCNIHAN
EPSS
0.73%
50.5th percentile
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 13.0 | 13.0 |
| apple | macos | >= unspecified < 13 | 13 |
| apple | macos_ventura | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-32895: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 4.7
CVE-2022-32895 [MEDIUM] CVE-2022-32895: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-32895
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: A race condition was addressed with improved state handling.
GHSA
GHSA-vfgr-2rxv-7v7g: A race condition was addressed with improved state handling
ghsa_unreviewed·2022-11-02
CVE-2022-32895 [MEDIUM] CWE-362 GHSA-vfgr-2rxv-7v7g: A race condition was addressed with improved state handling
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system.
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2019-8561 A Hard-to-Banish PackageKit Framework Vulnerability in macOS
blogs_trendmicro·2022-11-11·CVSS 7.8
CVE-2019-8561 [HIGH] CVE-2019-8561 A Hard-to-Banish PackageKit Framework Vulnerability in macOS
Exploits & Vulnerabilities
# CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS
This blog entry details our investigation of CVE-2019-8561, a vulnerability that exists in the macOS PackageKit framework, a component used to install software installer packages (PKG files).
By: Mickey Jin
2022/11/11
Read time: ( words)
Save to Folio
This blog entry details our investigation of CVE-2019-8561, a vulnerability that exists in the macOS PackageKit framework, a component used to install software installer packages (PKG files). We discuss how Apple patched it, how we exploited this vulnerability after it was addressed, and how Apple patched it again.
We also disclosed more than 15 critical SIP-bypass vulnerabilities to Apple and talked about some of them at the Power
Trendmicro
CVE-2019-8561 A Hard-to-Banish PackageKit Framework Vulnerability in macOS
blogs_trendmicro·2022-11-11·CVSS 7.8
CVE-2019-8561 [HIGH] CVE-2019-8561 A Hard-to-Banish PackageKit Framework Vulnerability in macOS
Exploits & Vulnerabilities
# CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS
This blog entry details our investigation of CVE-2019-8561, a vulnerability that exists in the macOS PackageKit framework, a component used to install software installer packages (PKG files).
By: Mickey Jin
Nov 11, 2022
Read time: ( words)
Save to Folio
This blog entry details our investigation of CVE-2019-8561, a vulnerability that exists in the macOS PackageKit framework, a component used to install software installer packages (PKG files). We discuss how Apple patched it, how we exploited this vulnerability after it was addressed, and how Apple patched it again.
We also disclosed more than 15 critical SIP-bypass vulnerabilities to Apple and talked about some of them at the Powe
2022-11-01
Published