Junglewise Threat Intelligence

CVE-2022-48503: Apple Multiple Products code execution in JavaScriptCore

CVE-2022-48503 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-10-20

Technologies: Apple Tvos, Apple Safari, Apple macOS Monterey, Apple watchOS, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's web processing engine affects iPhones, iPads, Macs, Apple TVs, and Apple Watches. By tricking a user into visiting a malicious website, an attacker could take control of the device and execute unauthorized commands. This issue has been reported as being actively exploited in the wild, posing a significant risk to user data and device security.

Technical details

This vulnerability is classified as an improper validation of array index (CWE-129) within the JavaScriptCore component of Apple's operating systems and Safari browser. The root cause is a lack of sufficient bounds checking when processing web content. An attacker can exploit this by hosting a specially crafted website; when a user visits the site, the engine fails to validate array boundaries, leading to arbitrary code execution. This flaw has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active use by threat actors. Patches are available in macOS Monterey 12.5, iOS/iPadOS 15.6, tvOS 15.6, watchOS 8.7, and Safari 15.6.

Affected products

  • Apple macOS Monterey 12.0.0 to 12.5
  • Apple iOS and iPadOS Before 15.6
  • Apple tvOS Before 15.6
  • Apple watchOS Before 8.7
  • Apple Safari Before 15.6

Timeline

  • 2023-08-14: disclosed: Initial NVD publication
  • 2025-10-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2022-07-20: patched: Vendor released security updates for affected products

Related threats