Macos Apple Macos

Do you want an email whenever new security vulnerabilities are reported in Apple Macos?

Recent Apple Macos Security Advisories

Advisory Title Published
HT213650 GarageBand for macOS 10.4.8 Security Content March 7, 2023
HT213633 macOS Ventura 13.2.1 Security Content February 13, 2023
HT213604 macOS Monterey 12.6.3 Security Content January 23, 2023
HT213603 macOS Big Sur 11.7.3 Security Content January 23, 2023
HT213605 macOS Ventura 13.2 Security Content January 23, 2023
HT213532 macOS Ventura 13.1 Security Content December 13, 2022
HT213534 macOS Big Sur 11.7.2 Security Content December 13, 2022
HT213533 macOS Monterey 12.6.2 Security Content December 13, 2022
HT213504 macOS Ventura 13.0.1 Security Content November 9, 2022
HT213488 macOS Ventura 13 Security Content October 24, 2022

Known Exploited Apple Macos Vulnerabilities

The following Apple Macos vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. CVE-2022-22675 April 4, 2022
Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. CVE-2022-22674 April 4, 2022
Apple macOS Input Validation Error A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30713 November 3, 2021
Apple macOS Policy Subsystem Gatekeeper Bypass A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30657 November 3, 2021

By the Year

In 2023 there have been 42 vulnerabilities in Apple Macos with an average score of 6.5 out of ten. Last year Macos had 379 security vulnerabilities published. Right now, Macos is on track to have less security vulnerabilities in 2023 than it did last year. Last year, the average CVE base score was greater by 0.63

Year Vulnerabilities Average Score
2023 42 6.50
2022 379 7.12
2021 463 7.04
2020 41 7.01
2019 1 7.40
2018 0 0.00

It may take a day or so for new Macos vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple Macos Security Vulnerabilities

An information disclosure issue was addressed by removing the vulnerable code

CVE-2023-23502 5.5 - Medium - February 27, 2023

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to determine kernel memory layout.

The issue was addressed with improved memory handling

CVE-2023-23517 8.8 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. Processing maliciously crafted web content may lead to arbitrary code execution.

A use after free issue was addressed with improved memory management

CVE-2023-23514 7.8 - High - February 27, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1. An app may be able to execute arbitrary code with kernel privileges..

Dangling pointer

A buffer overflow issue was addressed with improved memory handling

CVE-2023-23513 9.8 - Critical - February 27, 2023

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

Classic Buffer Overflow

A permissions issue was addressed with improved validation

CVE-2023-23510 5.5 - Medium - February 27, 2023

A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a users Safari history.

A permissions issue was addressed with improved validation

CVE-2023-23506 5.5 - Medium - February 27, 2023

A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive data.

A privacy issue was addressed with improved private data redaction for log entries

CVE-2023-23505 3.3 - Low - February 27, 2023

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access information about a users contacts.

Insertion of Sensitive Information into Log File

An issue with app access to camera data was addressed with improved logic

CVE-2022-42838 3.3 - Low - February 27, 2023

An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed.

Operation on a Resource after Expiration or Release

An out-of-bounds read was addressed with improved input validation

CVE-2022-42833 7.8 - High - February 27, 2023

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2022-32900 7.8 - High - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to gain elevated privileges.

This issue was addressed by enabling hardened runtime

CVE-2022-32896 5.5 - Medium - February 27, 2023

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. A user may be able to view sensitive user information.

Exposure of Resource to Wrong Sphere

A logic issue was addressed with improved restrictions

CVE-2022-22668 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A malicious application may be able to leak sensitive user information.

The issue was addressed with improved memory handling

CVE-2023-23504 7.8 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code with kernel privileges.

A logic issue was addressed with improved state management

CVE-2023-23503 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.

The issue was addressed with improved memory handling

CVE-2023-23518 8.8 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. Processing maliciously crafted web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2

CVE-2023-23501 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory..

Exposure of Resource to Wrong Sphere

The issue was addressed with improved memory handling

CVE-2023-23500 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to leak sensitive kernel state.

This issue was addressed by enabling hardened runtime

CVE-2023-23499 5.5 - Medium - February 27, 2023

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access user-sensitive data.

A logic issue was addressed with improved state management

CVE-2023-23498 3.3 - Low - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, iOS 16.3 and iPadOS 16.3. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account.

A logic issue was addressed with improved state management

CVE-2023-23497 7.8 - High - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to gain root privileges.

The issue was addressed with improved checks

CVE-2023-23496 8.8 - High - February 27, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.

A logic issue was addressed with improved state management

CVE-2023-23493 3.3 - Low - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An encrypted volume may be unmounted and remounted by a different user without prompting for the password.

authentification

This issue was addressed with improved checks

CVE-2022-46723 9.8 - Critical - February 27, 2023

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.

A race condition was addressed with additional validation

CVE-2022-46713 4.7 - Medium - February 27, 2023

A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.

Race Condition

A use after free issue was addressed with improved memory management

CVE-2022-46712 7.8 - High - February 27, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges.

Dangling pointer

A spoofing issue existed in the handling of URLs

CVE-2022-46705 4.3 - Medium - February 27, 2023

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.

Improper Input Validation

A logic issue was addressed with improved state management

CVE-2022-46704 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to modify protected parts of the file system.

A memory corruption issue was addressed with improved state management

CVE-2023-23519 7.5 - High - February 27, 2023

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, iOS 16.3 and iPadOS 16.3, watchOS 9.3. Processing an image may lead to a denial-of-service.

Memory Corruption

The issue was addressed with improved handling of caches

CVE-2023-23512 6.5 - Medium - February 27, 2023

The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, iOS 16.3 and iPadOS 16.3, watchOS 9.3. Visiting a website may lead to an app denial-of-service.

The issue was addressed with improved memory handling

CVE-2023-23511 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.

The issue was addressed with improved memory handling

CVE-2023-23508 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to bypass Privacy preferences.

The issue was addressed with improved bounds checks

CVE-2023-23507 7.8 - High - February 27, 2023

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to execute arbitrary code with kernel privileges.

A validation issue existed in the handling of symlinks

CVE-2022-22582 5.5 - Medium - February 27, 2023

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.

insecure temporary file

A logic issue was addressed with improved state management

CVE-2020-9846 5.3 - Medium - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to access local users' Apple IDs.

A use after free issue was addressed with improved memory management

CVE-2022-42826 8.8 - High - February 27, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

The issue was addressed with improved memory handling

CVE-2023-23531 8.6 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

The issue was addressed with improved memory handling

CVE-2023-23530 8.6 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

A type confusion issue was addressed with improved checks

CVE-2023-23529 8.8 - High - February 27, 2023

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Object Type Confusion

A denial-of-service issue was addressed with improved input validation

CVE-2023-23524 7.5 - High - February 27, 2023

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, tvOS 16.3.2, watchOS 9.3.1. Processing a maliciously crafted certificate may lead to a denial-of-service.

Resource Exhaustion

A privacy issue was addressed with improved handling of temporary files

CVE-2023-23522 5.5 - Medium - February 27, 2023

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.2.1. An app may be able to observe unprotected user data..

A race condition was addressed with additional validation

CVE-2023-23520 5.9 - Medium - February 27, 2023

A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.

TOCTTOU

A logic issue was addressed with improved state management

CVE-2022-32902 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.

An issue existed with the file paths used to store website data

CVE-2022-32833 5.3 - Medium - December 15, 2022

An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.

Exposure of Resource to Wrong Sphere

The issue was addressed with improved bounds checks

CVE-2022-32943 5.3 - Medium - December 15, 2022

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.

An access issue was addressed with additional sandbox restrictions on third-party apps

CVE-2022-32945 4.3 - Medium - December 15, 2022

An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.

AuthZ

A logic issue was addressed with improved state management

CVE-2022-42855 7.1 - High - December 15, 2022

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

This issue was addressed with improved checks

CVE-2022-42861 8.8 - High - December 15, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.

This issue was addressed by removing the vulnerable code

CVE-2022-42862 5.5 - Medium - December 15, 2022

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.

A type confusion issue was addressed with improved state handling

CVE-2022-42856 8.8 - High - December 15, 2022

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..

Object Type Confusion

An out-of-bounds access issue was addressed with improved bounds checking

CVE-2022-46697 7.8 - High - December 15, 2022

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.

Memory Corruption

The issue was addressed with improved bounds checks

CVE-2022-46701 7.8 - High - December 15, 2022

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.

Buffer Overflow

This issue was addressed by enabling hardened runtime

CVE-2022-42865 5.5 - Medium - December 15, 2022

This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

Multiple issues were addressed by removing the vulnerable code

CVE-2022-42859 5.5 - Medium - December 15, 2022

Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.

A race condition was addressed with additional validation

CVE-2022-46689 7 - High - December 15, 2022

A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

Race Condition

An out-of-bounds write was addressed with improved input validation

CVE-2022-32860 7.8 - High - December 15, 2022

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.

Memory Corruption

The issue was addressed with improved memory handling

CVE-2022-32942 7.8 - High - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. An app may be able to execute arbitrary code with kernel privileges.

A race condition was addressed with improved state handling

CVE-2022-42864 7 - High - December 15, 2022

A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

Race Condition

An out-of-bounds write issue was addressed with improved input validation

CVE-2022-46690 7.8 - High - December 15, 2022

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory consumption issue was addressed with improved memory handling

CVE-2022-46691 8.8 - High - December 15, 2022

A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

An out-of-bounds write issue was addressed with improved input validation

CVE-2022-46693 7.8 - High - December 15, 2022

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

An out-of-bounds read was addressed with improved bounds checking

CVE-2022-32948 7.8 - High - December 15, 2022

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

Out-of-bounds Read

An access issue was addressed with improved access restrictions

CVE-2022-42853 5.5 - Medium - December 15, 2022

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.

The issue was addressed with improved memory handling

CVE-2022-42854 5.5 - Medium - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1. An app may be able to disclose kernel memory.

A spoofing issue existed in the handling of URLs

CVE-2022-46695 6.5 - Medium - December 15, 2022

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.

Clickjacking

A memory corruption issue was addressed with improved input validation

CVE-2022-46696 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved checks

CVE-2022-46698 6.5 - Medium - December 15, 2022

A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.

A memory corruption issue was addressed with improved state management

CVE-2022-46699 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A memory corruption issue was addressed with improved input validation

CVE-2022-46700 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

An integer overflow was addressed with improved input validation

CVE-2022-42805 7.8 - High - December 15, 2022

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

Integer Overflow or Wraparound

A logic issue was addressed with improved checks

CVE-2022-42821 5.5 - Medium - December 15, 2022

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

The issue was addressed with improved memory handling

CVE-2022-42840 7.8 - High - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved memory handling

CVE-2022-42845 7.2 - High - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.

An out-of-bounds write issue was addressed with improved input validation

CVE-2022-42847 7.8 - High - December 15, 2022

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.

Memory Corruption

The issue was addressed with improved memory handling

CVE-2022-42852 6.5 - Medium - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

A memory corruption issue was addressed with improved state management

CVE-2022-42863 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

The issue was addressed with improved handling of caches

CVE-2022-42866 5.5 - Medium - December 15, 2022

The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.

A use after free issue was addressed with improved memory management

CVE-2022-42867 8.8 - High - December 15, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A logic issue was addressed with improved state management

CVE-2022-46692 5.5 - Medium - December 15, 2022

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

An issue existed in the parsing of URLs

CVE-2022-42837 9.8 - Critical - December 15, 2022

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.

A type confusion issue was addressed with improved checks

CVE-2022-42841 7.8 - High - December 15, 2022

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Processing a maliciously crafted package may lead to arbitrary code execution.

Object Type Confusion

The issue was addressed with improved memory handling

CVE-2022-42842 9.8 - Critical - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

This issue was addressed with improved data protection

CVE-2022-42843 5.5 - Medium - December 15, 2022

This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.

Exposure of Resource to Wrong Sphere

curl can be told to parse a `.netrc` file for credentials

CVE-2022-35260 6.5 - Medium - December 05, 2022

curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.

Memory Corruption

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used

CVE-2022-32221 9.8 - Critical - December 05, 2022

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

Exposure of Resource to Wrong Sphere

An issue was discovered in libxml2 before 2.10.3

CVE-2022-40304 7.8 - High - November 23, 2022

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

XXE

An issue was discovered in libxml2 before 2.10.3

CVE-2022-40303 7.5 - High - November 23, 2022

An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.

Integer Overflow or Wraparound

This issue was addressed with improved data protection

CVE-2022-32867 2.4 - Low - November 01, 2022

This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.

A logic issue was addressed with improved state management

CVE-2022-32875 5 - Medium - November 01, 2022

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6. An app may be able to read sensitive location information.

A logic issue was addressed with improved state management

CVE-2022-32870 2.4 - Low - November 01, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.

The issue was addressed with improved memory handling

CVE-2022-32866 7.8 - High - November 01, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved memory handling

CVE-2022-32865 7.8 - High - November 01, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved memory handling

CVE-2022-32947 7.8 - High - November 01, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.

A memory corruption issue was addressed with improved state management

CVE-2022-32944 7.8 - High - November 01, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved bounds checks

CVE-2022-32941 9.8 - Critical - November 01, 2022

The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A buffer overflow may result in arbitrary code execution.

Classic Buffer Overflow

The issue was addressed with improved bounds checks

CVE-2022-32940 7.8 - High - November 01, 2022

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.

A parsing issue in the handling of directory paths was addressed with improved path validation

CVE-2022-32938 5.3 - Medium - November 01, 2022

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. A shortcut may be able to check the existence of an arbitrary path on the file system.

An out-of-bounds read was addressed with improved input validation

CVE-2022-32936 5.5 - Medium - November 01, 2022

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose kernel memory.

Out-of-bounds Read

A lock screen issue was addressed with improved state management

CVE-2022-32935 4.6 - Medium - November 01, 2022

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.

The issue was addressed with improved memory handling

CVE-2022-32934 8.8 - High - November 01, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. A remote user may be able to cause kernel code execution.

A logic issue was addressed with improved restrictions

CVE-2022-32928 5.3 - Medium - November 01, 2022

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple Watch OS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple Macos
Product

subscribe