peter bassill · operator
$ cve CVE-2022-32845 JSON

CVE-2022-32845

10.0
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 92)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS5.37% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-693
On CISA KEVno
Public exploitnone known
Published2022-09-23
Last modified2026-06-17

Affected (4)

VendorProduct
appleipados
appleiphone os
applemacos
applewatchos

References

→ the Explorer  ·  watch your stack  ·  NVD