peter bassill · operator
$ cve CVE-2022-32839 JSON

CVE-2022-32839

9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.82% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2022-08-24
Last modified2026-06-17

Affected (6)

VendorProduct
appleipados
appleiphone os
applemac os x
applemacos
appletvos
applewatchos

References

→ the Explorer  ·  watch your stack  ·  NVD