Junglewise Threat Intelligence

CVE-2022-32893: Apple iOS and macOS Out-of-Bounds Write Vulnerability

CVE-2022-32893 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-08-18

Technologies: Cisco IOS, Apple macOS, Apple iPadOS, Apple Safari, Apple macOS Monterey. Vendors: Cisco, Apple.

Executive brief

An out-of-bounds write vulnerability in Apple iOS, iPadOS, macOS, and Safari allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved bounds checking and has been reported as being actively exploited in the wild.

Affected products

  • Apple iOS before 15.6.1
  • Apple iPadOS before 15.6.1
  • Apple macOS Monterey before 12.5.1
  • Apple Safari before 15.6.1

Timeline

  • 2022-08-18: disclosed
  • 2022-08-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-18: patched: Fixed in iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1
  • exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats