Apple Watch OS Apple Watch Operating System
Recent Apple Watch OS Security Advisories
Advisory | Title | Published |
---|---|---|
HT213599 | watchOS 9.3 Security Content | January 23, 2023 |
HT213536 | watchOS 9.2 Security Content | December 13, 2022 |
HT213491 | watchOS 9.1 Security Content | October 24, 2022 |
HT213486 | watchOS 9 Security Content | September 12, 2022 |
HT213340 | watchOS 8.7 Security Content | July 20, 2022 |
HT213253 | watchOS 8.6 Security Content | May 16, 2022 |
HT213193 | watchOS 8.5 Security Content | March 14, 2022 |
HT213059 | watchOS 8.4 Security Content | January 26, 2022 |
HT212975 | watchOS 8.3 Security Content | December 13, 2021 |
HT212874 | watchOS 8.1 Security Content | October 25, 2021 |
By the Year
In 2023 there have been 0 vulnerabilities in Apple Watch OS . Last year Watch OS had 150 security vulnerabilities published. Right now, Watch OS is on track to have less security vulnerabilities in 2023 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 0 | 0.00 |
2022 | 150 | 7.24 |
2021 | 252 | 7.19 |
2020 | 177 | 7.31 |
2019 | 201 | 7.70 |
2018 | 56 | 7.54 |
It may take a day or so for new Watch OS vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apple Watch OS Security Vulnerabilities
The issue was addressed with improved handling of caches
CVE-2022-42866
5.5 - Medium
- December 15, 2022
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
This issue was addressed by enabling hardened runtime
CVE-2022-42865
5.5 - Medium
- December 15, 2022
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
Multiple issues were addressed by removing the vulnerable code
CVE-2022-42859
5.5 - Medium
- December 15, 2022
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.
A race condition was addressed with additional validation
CVE-2022-46689
7 - High
- December 15, 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
A race condition was addressed with improved state handling
CVE-2022-42864
7 - High
- December 15, 2022
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46690
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
A memory consumption issue was addressed with improved memory handling
CVE-2022-46691
8.8 - High
- December 15, 2022
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46693
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.
Memory Corruption
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-46694
7.8 - High
- December 15, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.
Memory Corruption
A spoofing issue existed in the handling of URLs
CVE-2022-46695
6.5 - Medium
- December 15, 2022
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
Clickjacking
A memory corruption issue was addressed with improved input validation
CVE-2022-46696
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A logic issue was addressed with improved checks
CVE-2022-46698
6.5 - Medium
- December 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
A memory corruption issue was addressed with improved state management
CVE-2022-46699
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A memory corruption issue was addressed with improved input validation
CVE-2022-46700
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-42845
7.2 - High
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-42852
6.5 - Medium
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
A memory corruption issue was addressed with improved state management
CVE-2022-42863
8.8 - High
- December 15, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A use after free issue was addressed with improved memory management
CVE-2022-42867
8.8 - High
- December 15, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A logic issue was addressed with improved state management
CVE-2022-46692
5.5 - Medium
- December 15, 2022
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
An issue existed in the parsing of URLs
CVE-2022-42837
9.8 - Critical
- December 15, 2022
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.
The issue was addressed with improved memory handling
CVE-2022-42842
9.8 - Critical
- December 15, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
This issue was addressed with improved data protection
CVE-2022-42843
5.5 - Medium
- December 15, 2022
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
Exposure of Resource to Wrong Sphere
An access issue existed with privileged API calls
CVE-2022-42849
7.8 - High
- December 15, 2022
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
AuthZ
An issue was discovered in libxml2 before 2.10.3
CVE-2022-40304
7.8 - High
- November 23, 2022
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
XXE
An issue was discovered in libxml2 before 2.10.3
CVE-2022-40303
7.5 - High
- November 23, 2022
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
Integer Overflow or Wraparound
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-32888
8.8 - High
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-32889
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32898
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with additional restrictions on the observability of app states
CVE-2022-32913
3.3 - Low
- November 01, 2022
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. A sandboxed app may be able to determine which app is currently using the camera.
A use after free issue was addressed with improved memory management
CVE-2022-26709
8.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A use after free issue was addressed with improved memory management
CVE-2022-26710
8.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A memory corruption issue was addressed with improved state management
CVE-2022-26716
8.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
A use after free issue was addressed with improved memory management
CVE-2022-26717
8.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A memory corruption issue was addressed with improved state management
CVE-2022-26719
8.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
This issue was addressed with improved entitlements
CVE-2022-32835
3.3 - Low
- November 01, 2022
This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to read a persistent device identifier.
The issue was addressed with improved memory handling
CVE-2022-32858
5.5 - Medium
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leak sensitive kernel state.
A logic issue was addressed with improved restrictions
CVE-2022-32881
5.5 - Medium
- November 01, 2022
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to modify protected parts of the file system.
The issue was addressed with improved memory handling
CVE-2022-32899
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
An access issue was addressed with additional sandbox restrictions
CVE-2022-42811
5.5 - Medium
- November 01, 2022
An access issue was addressed with additional sandbox restrictions. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to access user-sensitive data.
A certificate validation issue existed in the handling of WKWebView
CVE-2022-42813
9.8 - Critical
- November 01, 2022
A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.
Improper Certificate Validation
A logic issue was addressed with improved state management
CVE-2022-42817
6.5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. Visiting a maliciously crafted website may leak sensitive data.
A type confusion issue was addressed with improved memory handling
CVE-2022-42823
8.8 - High
- November 01, 2022
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Object Type Confusion
A logic issue was addressed with improved state management
CVE-2022-42824
5.5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
This issue was addressed by removing additional entitlements
CVE-2022-42825
5.5 - Medium
- November 01, 2022
This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-42827
7.8 - High
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Memory Corruption
The issue was addressed with improved memory handling
CVE-2022-42798
5.5 - Medium
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. Parsing a maliciously crafted audio file may lead to disclosure of user information.
The issue was addressed with improved UI handling
CVE-2022-42799
6.1 - Medium
- November 01, 2022
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
Clickjacking
This issue was addressed with improved checks
CVE-2022-42800
7.8 - High
- November 01, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A user may be able to cause unexpected app termination or arbitrary code execution.
A logic issue was addressed with improved checks
CVE-2022-42801
7.8 - High
- November 01, 2022
A logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1. An app may be able to execute arbitrary code with kernel privileges.
A race condition was addressed with improved locking
CVE-2022-42803
7 - High
- November 01, 2022
A race condition was addressed with improved locking. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1. An app may be able to execute arbitrary code with kernel privileges.
Race Condition
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-42808
9.8 - Critical
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
Memory Corruption
This issue was addressed with improved checks
CVE-2022-32907
7.8 - High
- November 01, 2022
This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
A memory consumption issue was addressed with improved memory handling
CVE-2022-42795
8.8 - High
- November 01, 2022
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
Memory Corruption
A logic issue was addressed with improved state management
CVE-2022-32879
2.4 - Low
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, tvOS 16. A user with physical access to a device may be able to access contacts from the lock screen.
A use after free issue was addressed with improved memory management
CVE-2022-32903
7.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
Dangling pointer
A use after free issue was addressed with improved memory management
CVE-2022-32914
7.8 - High
- November 01, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
Dangling pointer
A correctness issue in the JIT was addressed with improved checks
CVE-2022-32923
6.5 - Medium
- November 01, 2022
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.
The issue was addressed with improved memory handling
CVE-2022-32924
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-32925
7.1 - High
- November 01, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.
Memory Corruption
The issue was addressed with improved bounds checks
CVE-2022-32926
6.7 - Medium
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16. An app with root privileges may be able to execute arbitrary code with kernel privileges.
A logic issue was addressed with improved restrictions
CVE-2022-32928
5.3 - Medium
- November 01, 2022
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.
The issue was addressed with improved memory handling
CVE-2022-32932
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved bounds checks
CVE-2022-32940
7.8 - High
- November 01, 2022
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
A memory corruption issue was addressed with improved state management
CVE-2022-32944
7.8 - High
- November 01, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32947
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
The issue was addressed with improved memory handling
CVE-2022-32866
7.8 - High
- November 01, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.
A logic issue was addressed with improved state management
CVE-2022-32870
2.4 - Low
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.
A logic issue was addressed with improved state management
CVE-2022-32875
5 - Medium
- November 01, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6. An app may be able to read sensitive location information.
A type confusion issue was addressed with improved state handling
CVE-2022-32814
7.8 - High
- September 23, 2022
A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Object Type Confusion
A buffer overflow issue was addressed with improved memory handling
CVE-2022-22629
8.8 - High
- September 23, 2022
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-32820
7.8 - High
- September 23, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
Memory Corruption
An out-of-bounds read was addressed with improved input validation
CVE-2020-36521
7.1 - High
- September 23, 2022
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
Out-of-bounds Read
The issue was addressed with improved memory handling
CVE-2022-32841
5.5 - Medium
- September 23, 2022
The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted image may result in disclosure of process memory.
The issue was addressed with improved memory handling
CVE-2022-32832
6.7 - Medium
- September 23, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
This issue was addressed with improved checks
CVE-2022-32847
9.1 - Critical
- September 23, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
This issue was addressed with improved checks
CVE-2022-32845
10 - Critical
- September 23, 2022
This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.
The issue was addressed with improved memory handling
CVE-2022-32825
5.5 - Medium
- September 23, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
A memory initialization issue was addressed with improved memory handling
CVE-2022-32823
5.5 - Medium
- September 23, 2022
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information.
Improper Initialization
A memory corruption issue was addressed with improved validation
CVE-2022-32821
7.8 - High
- September 23, 2022
A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
An authorization issue was addressed with improved state management
CVE-2022-32826
7.8 - High
- September 23, 2022
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.
A logic issue was addressed with improved state management
CVE-2022-32819
7.8 - High
- September 23, 2022
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.
An out-of-bounds read issue was addressed with improved bounds checking
CVE-2022-32817
5.5 - Medium
- September 23, 2022
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
Out-of-bounds Read
The issue was addressed with improved UI handling
CVE-2022-32816
6.5 - Medium
- September 23, 2022
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
The issue was addressed with improved memory handling
CVE-2022-32815
7.8 - High
- September 23, 2022
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
An out-of-bounds write issue was addressed with improved input validation
CVE-2022-32792
8.8 - High
- September 23, 2022
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
This issue was addressed with improved checks
CVE-2022-32790
7.5 - High
- September 23, 2022
This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Big Sur 11.6.6, Security Update 2022-004 Catalina. A remote user may be able to cause a denial-of-service.
A memory corruption issue was addressed with improved state management
CVE-2022-22610
8.8 - High
- September 23, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to code execution.
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-32787
8.8 - High
- September 23, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. Processing maliciously crafted web content may lead to arbitrary code execution.
Memory Corruption
A logic issue was addressed with improved state management
CVE-2022-22637
8.8 - High
- September 23, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
A use after free issue was addressed with improved memory management
CVE-2022-22628
8.8 - High
- September 23, 2022
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Dangling pointer
A memory corruption issue was addressed with improved state management
CVE-2022-26700
8.8 - High
- September 23, 2022
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.
The issue was addressed with improved memory handling
CVE-2022-32911
7.8 - High
- September 20, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.
A memory corruption issue was addressed with improved input validation
CVE-2022-32908
7.8 - High
- September 20, 2022
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.
Memory Corruption
A logic issue was addressed with improved restrictions
CVE-2022-32883
5.5 - Medium
- September 20, 2022
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
Exposure of Resource to Wrong Sphere
The issue was addressed with improved memory handling
CVE-2022-32864
5.5 - Medium
- September 20, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to disclose kernel memory.
This issue was addressed with improved checks
CVE-2022-32854
5.5 - Medium
- September 20, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.
AuthZ
A buffer overflow was addressed with improved bounds checking
CVE-2022-32788
9.8 - Critical
- September 20, 2022
A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.
Classic Buffer Overflow
An out-of-bounds write issue was addressed with improved bounds checking
CVE-2022-32894
7.8 - High
- August 24, 2022
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Memory Corruption
This issue was addressed by using HTTPS when sending information over the network
CVE-2022-32857
4.3 - Medium
- August 24, 2022
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a users activity.
The issue was addressed with improved memory handling
CVE-2022-32813
7.8 - High
- August 24, 2022
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apple Mac OSX or by Apple? Click the Watch button to subscribe.
