Apple Macos
Recent Apple Macos Security Advisories
Advisory | Title | Published |
---|---|---|
HT213650 | GarageBand for macOS 10.4.8 Security Content | March 7, 2023 |
HT213633 | macOS Ventura 13.2.1 Security Content | February 13, 2023 |
HT213604 | macOS Monterey 12.6.3 Security Content | January 23, 2023 |
HT213603 | macOS Big Sur 11.7.3 Security Content | January 23, 2023 |
HT213605 | macOS Ventura 13.2 Security Content | January 23, 2023 |
HT213532 | macOS Ventura 13.1 Security Content | December 13, 2022 |
HT213534 | macOS Big Sur 11.7.2 Security Content | December 13, 2022 |
HT213533 | macOS Monterey 12.6.2 Security Content | December 13, 2022 |
HT213504 | macOS Ventura 13.0.1 Security Content | November 9, 2022 |
HT213488 | macOS Ventura 13 Security Content | October 24, 2022 |
Known Exploited Apple Macos Vulnerabilities
The following Apple Macos vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
Title | Description | Added |
---|---|---|
Apple macOS Out-of-Bounds Write Vulnerability | macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. CVE-2022-22675 | April 4, 2022 |
Apple macOS Out-of-Bounds Read Vulnerability | macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. CVE-2022-22674 | April 4, 2022 |
Apple macOS Input Validation Error | A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30713 | November 3, 2021 |
Apple macOS Policy Subsystem Gatekeeper Bypass | A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited. CVE-2021-30657 | November 3, 2021 |
By the Year
In 2023 there have been 42 vulnerabilities in Apple Macos with an average score of 6.5 out of ten. Last year Macos had 379 security vulnerabilities published. Right now, Macos is on track to have less security vulnerabilities in 2023 than it did last year. Last year, the average CVE base score was greater by 0.63
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 42 | 6.50 |
2022 | 379 | 7.12 |
2021 | 463 | 7.04 |
2020 | 41 | 7.01 |
2019 | 1 | 7.40 |
2018 | 0 | 0.00 |
It may take a day or so for new Macos vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apple Macos Security Vulnerabilities
An information disclosure issue was addressed by removing the vulnerable code
CVE-2023-23502
5.5 - Medium
- February 27, 2023
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to determine kernel memory layout.
The issue was addressed with improved memory handling
CVE-2023-23517
8.8 - High
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. Processing maliciously crafted web content may lead to arbitrary code execution.
A use after free issue was addressed with improved memory management
CVE-2023-23514
7.8 - High
- February 27, 2023
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1. An app may be able to execute arbitrary code with kernel privileges..
Dangling pointer
A buffer overflow issue was addressed with improved memory handling
CVE-2023-23513
9.8 - Critical
- February 27, 2023
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.
Classic Buffer Overflow
A permissions issue was addressed with improved validation
CVE-2023-23510
5.5 - Medium
- February 27, 2023
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a users Safari history.
A permissions issue was addressed with improved validation
CVE-2023-23506
5.5 - Medium
- February 27, 2023
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive data.
A privacy issue was addressed with improved private data redaction for log entries
CVE-2023-23505
3.3 - Low
- February 27, 2023
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access information about a users contacts.
Insertion of Sensitive Information into Log File
An issue with app access to camera data was addressed with improved logic
CVE-2022-42838
3.3 - Low
- February 27, 2023
An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed.
Operation on a Resource after Expiration or Release
An out-of-bounds read was addressed with improved input validation
CVE-2022-42833
7.8 - High
- February 27, 2023
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
Out-of-bounds Read
A logic issue was addressed with improved state management
CVE-2022-32900
7.8 - High
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to gain elevated privileges.
This issue was addressed by enabling hardened runtime
CVE-2022-32896
5.5 - Medium
- February 27, 2023
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. A user may be able to view sensitive user information.
Exposure of Resource to Wrong Sphere
A logic issue was addressed with improved restrictions
CVE-2022-22668
5.5 - Medium
- February 27, 2023
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A malicious application may be able to leak sensitive user information.
The issue was addressed with improved memory handling
CVE-2023-23504
7.8 - High
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code with kernel privileges.
A logic issue was addressed with improved state management
CVE-2023-23503
5.5 - Medium
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.
The issue was addressed with improved memory handling
CVE-2023-23518
8.8 - High
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. Processing maliciously crafted web content may lead to arbitrary code execution.
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2
CVE-2023-23501
5.5 - Medium
- February 27, 2023
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory..
Exposure of Resource to Wrong Sphere
The issue was addressed with improved memory handling
CVE-2023-23500
5.5 - Medium
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to leak sensitive kernel state.
This issue was addressed by enabling hardened runtime
CVE-2023-23499
5.5 - Medium
- February 27, 2023
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access user-sensitive data.
A logic issue was addressed with improved state management
CVE-2023-23498
3.3 - Low
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, iOS 16.3 and iPadOS 16.3. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account.
A logic issue was addressed with improved state management
CVE-2023-23497
7.8 - High
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to gain root privileges.
The issue was addressed with improved checks
CVE-2023-23496
8.8 - High
- February 27, 2023
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
A logic issue was addressed with improved state management
CVE-2023-23493
3.3 - Low
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An encrypted volume may be unmounted and remounted by a different user without prompting for the password.
authentification
This issue was addressed with improved checks
CVE-2022-46723
9.8 - Critical
- February 27, 2023
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.
A race condition was addressed with additional validation
CVE-2022-46713
4.7 - Medium
- February 27, 2023
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.
Race Condition
A use after free issue was addressed with improved memory management
CVE-2022-46712
7.8 - High
- February 27, 2023
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges.
Dangling pointer
A spoofing issue existed in the handling of URLs
CVE-2022-46705
4.3 - Medium
- February 27, 2023
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.
Improper Input Validation
A logic issue was addressed with improved state management
CVE-2022-46704
5.5 - Medium
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to modify protected parts of the file system.
A memory corruption issue was addressed with improved state management
CVE-2023-23519
7.5 - High
- February 27, 2023
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, iOS 16.3 and iPadOS 16.3, watchOS 9.3. Processing an image may lead to a denial-of-service.
Memory Corruption
The issue was addressed with improved handling of caches
CVE-2023-23512
6.5 - Medium
- February 27, 2023
The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, iOS 16.3 and iPadOS 16.3, watchOS 9.3. Visiting a website may lead to an app denial-of-service.
The issue was addressed with improved memory handling
CVE-2023-23511
5.5 - Medium
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.
The issue was addressed with improved memory handling
CVE-2023-23508
5.5 - Medium
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, macOS Big Sur 11.7.3. An app may be able to bypass Privacy preferences.
The issue was addressed with improved bounds checks
CVE-2023-23507
7.8 - High
- February 27, 2023
The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to execute arbitrary code with kernel privileges.
A validation issue existed in the handling of symlinks
CVE-2022-22582
5.5 - Medium
- February 27, 2023
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.
insecure temporary file
A logic issue was addressed with improved state management
CVE-2020-9846
5.3 - Medium
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to access local users' Apple IDs.
A use after free issue was addressed with improved memory management
CVE-2022-42826
8.8 - High
- February 27, 2023
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
The issue was addressed with improved memory handling
CVE-2023-23531
8.6 - High
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
The issue was addressed with improved memory handling
CVE-2023-23530
8.6 - High
- February 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
A type confusion issue was addressed with improved checks
CVE-2023-23529
8.8 - High
- February 27, 2023
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Object Type Confusion
A denial-of-service issue was addressed with improved input validation
CVE-2023-23524
7.5 - High
- February 27, 2023
A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, tvOS 16.3.2, watchOS 9.3.1. Processing a maliciously crafted certificate may lead to a denial-of-service.
Resource Exhaustion
A privacy issue was addressed with improved handling of temporary files
CVE-2023-23522
5.5 - Medium
- February 27, 2023
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.2.1. An app may be able to observe unprotected user data..
A race condition was addressed with additional validation
CVE-2023-23520
5.9 - Medium
- February 27, 2023
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.
TOCTTOU
A logic issue was addressed with improved state management
CVE-2022-32902
5.5 - Medium
- February 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.
An issue existed with the file paths used to store website data
CVE-2022-32833
5.3 - Medium
- December 15, 2022
An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
Exposure of Resource to Wrong Sphere
The issue was addressed with improved bounds checks
CVE-2022-32943
5.3 - Medium
- December 15, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
An access issue was addressed with additional sandbox restrictions on third-party apps
CVE-2022-32945
4.3 - Medium
- December 15, 2022
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
AuthZ
A logic issue was addressed with improved state management
CVE-2022-42855
7.1 - High
- December 15, 2022
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
This issue was addressed with improved checks
CVE-2022-42861
8.8 - High
- December 15, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2. An app may be able to break out of its sandbox.
This issue was addressed by removing the vulnerable code
CVE-2022-42862
5.5 - Medium
- December 15, 2022
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.
A type confusion issue was addressed with improved state handling
CVE-2022-42856
8.8 - High
- December 15, 2022
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Object Type Confusion
An out-of-bounds access issue was addressed with improved bounds checking
CVE-2022-46697
7.8 - High
- December 15, 2022
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
The issue was addressed with improved bounds checks
CVE-2022-46701
7.8 - High
- December 15, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.
Buffer Overflow
This issue was addressed by enabling hardened runtime
CVE-2022-42865
5.5 - Medium
- December 15, 2022
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
Multiple issues were addressed by removing the vulnerable code
CVE-2022-42859
5.5 - Medium
- December 15, 2022
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.
A race condition was addressed with additional validation
CVE-2022-46689
7 - High
- December 15, 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
An out-of-bounds write was addressed with improved input validation
CVE-2022-32860
7.8 - High
- December 15, 2022
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-32942
7.8 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. An app may be able to execute arbitrary code with kernel privileges.
A race condition was addressed with improved state handling
CVE-2022-42864
7 - High
- December 15, 2022
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46690
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
A memory consumption issue was addressed with improved memory handling
CVE-2022-46691
8.8 - High
- December 15, 2022
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46693
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.
Memory Corruption
An out-of-bounds read was addressed with improved bounds checking
CVE-2022-32948
7.8 - High
- December 15, 2022
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Out-of-bounds Read
An access issue was addressed with improved access restrictions
CVE-2022-42853
5.5 - Medium
- December 15, 2022
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.
The issue was addressed with improved memory handling
CVE-2022-42854
5.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1. An app may be able to disclose kernel memory.
A spoofing issue existed in the handling of URLs
CVE-2022-46695
6.5 - Medium
- December 15, 2022
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
Clickjacking
A memory corruption issue was addressed with improved input validation
CVE-2022-46696
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A logic issue was addressed with improved checks
CVE-2022-46698
6.5 - Medium
- December 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
A memory corruption issue was addressed with improved state management
CVE-2022-46699
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A memory corruption issue was addressed with improved input validation
CVE-2022-46700
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
An integer overflow was addressed with improved input validation
CVE-2022-42805
7.8 - High
- December 15, 2022
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Integer Overflow or Wraparound
A logic issue was addressed with improved checks
CVE-2022-42821
5.5 - Medium
- December 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.
The issue was addressed with improved memory handling
CVE-2022-42840
7.8 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-42845
7.2 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-42847
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-42852
6.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
A memory corruption issue was addressed with improved state management
CVE-2022-42863
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
The issue was addressed with improved handling of caches
CVE-2022-42866
5.5 - Medium
- December 15, 2022
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
A use after free issue was addressed with improved memory management
CVE-2022-42867
8.8 - High
- December 15, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A logic issue was addressed with improved state management
CVE-2022-46692
5.5 - Medium
- December 15, 2022
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
An issue existed in the parsing of URLs
CVE-2022-42837
9.8 - Critical
- December 15, 2022
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.
A type confusion issue was addressed with improved checks
CVE-2022-42841
7.8 - High
- December 15, 2022
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Processing a maliciously crafted package may lead to arbitrary code execution.
Object Type Confusion
The issue was addressed with improved memory handling
CVE-2022-42842
9.8 - Critical
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
This issue was addressed with improved data protection
CVE-2022-42843
5.5 - Medium
- December 15, 2022
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
Exposure of Resource to Wrong Sphere
curl can be told to parse a `.netrc` file for credentials
CVE-2022-35260
6.5 - Medium
- December 05, 2022
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.
Memory Corruption
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used
CVE-2022-32221
9.8 - Critical
- December 05, 2022
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.
Exposure of Resource to Wrong Sphere
An issue was discovered in libxml2 before 2.10.3
CVE-2022-40304
7.8 - High
- November 23, 2022
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
XXE
An issue was discovered in libxml2 before 2.10.3
CVE-2022-40303
7.5 - High
- November 23, 2022
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
Integer Overflow or Wraparound
This issue was addressed with improved data protection
CVE-2022-32867
2.4 - Low
- November 01, 2022
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.
A logic issue was addressed with improved state management
CVE-2022-32875
5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6. An app may be able to read sensitive location information.
A logic issue was addressed with improved state management
CVE-2022-32870
2.4 - Low
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.
The issue was addressed with improved memory handling
CVE-2022-32866
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32865
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32947
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
A memory corruption issue was addressed with improved state management
CVE-2022-32944
7.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved bounds checks
CVE-2022-32941
9.8 - Critical
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A buffer overflow may result in arbitrary code execution.
Classic Buffer Overflow
The issue was addressed with improved bounds checks
CVE-2022-32940
7.8 - High
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
A parsing issue in the handling of directory paths was addressed with improved path validation
CVE-2022-32938
5.3 - Medium
- November 01, 2022
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. A shortcut may be able to check the existence of an arbitrary path on the file system.
An out-of-bounds read was addressed with improved input validation
CVE-2022-32936
5.5 - Medium
- November 01, 2022
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose kernel memory.
Out-of-bounds Read
A lock screen issue was addressed with improved state management
CVE-2022-32935
4.6 - Medium
- November 01, 2022
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.
The issue was addressed with improved memory handling
CVE-2022-32934
8.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. A remote user may be able to cause kernel code execution.
A logic issue was addressed with improved restrictions
CVE-2022-32928
5.3 - Medium
- November 01, 2022
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apple Watch OS or by Apple? Click the Watch button to subscribe.
