CVE-2022-42841Type Confusion in Apple Macos

CWE-843Type Confusion5 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 47.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Processing a maliciously crafted package may lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Appleapple/macos_monterey12.6.2
CVEListV5apple/macosunspecified11.7+2
NVDapple/macos11.011.7.2+2
Appleapple/macos_big_sur11.7.2

🔴Vulnerability Details

1
GHSA
GHSA-qhqr-ffv4-wv7f: A type confusion issue was addressed with improved checks2022-12-15

📋Vendor Advisories

3
Apple
CVE-2022-42841: macOS Monterey 12.6.22022-12-13
Apple
CVE-2022-42841: macOS Big Sur 11.7.22022-12-13
Apple
CVE-2022-42841: macOS Ventura 13.12022-12-13