CVE-2022-32945Improper Access Control in Apple Macos

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

CVEListV5apple/macosunspecified13
NVDapple/macos< 13.0
NVDapple/ipados< 16.0
NVDapple/iphone_os< 16.1

🔴Vulnerability Details

1
GHSA
GHSA-xh54-7xjp-2239: An access issue was addressed with additional sandbox restrictions on third-party apps2022-12-15

📋Vendor Advisories

2
Apple
CVE-2022-32945: macOS Ventura 132022-10-24
Apple
CVE-2022-32945: iOS 16.1 and iPadOS 162022-10-24