CVE-2022-48503 KEV
8.8
HIGH · CVSS 3.1 · EPSS 3.2% (pctl 88)
Patch first
On CISA KEV — known exploited in the wild, due 2025-11-10.
Description
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 3.21% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-129 |
| On CISA KEV | yes — remediate by 2025-11-10 |
| Public exploit | none known |
| Published | 2023-08-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apple Multiple Products Unspecified Vulnerability |
|---|---|
| Added | 2025-10-20 |
| Due | 2025-11-10 |
| Vendor / product | Apple / Multiple Products |
| Ransomware use | none reported |
Affected (6)
| Vendor | Product |
|---|---|
| apple | ipados |
| apple | iphone os |
| apple | macos |
| apple | safari |
| apple | tvos |
| apple | watchos |
References
- https://support.apple.com/en-us/HT213340
- https://support.apple.com/en-us/HT213341
- https://support.apple.com/en-us/HT213342
- https://support.apple.com/en-us/HT213345
- https://support.apple.com/en-us/HT213346
- https://support.apple.com/en-us/HT213340
- https://support.apple.com/en-us/HT213341
- https://support.apple.com/en-us/HT213342
- https://support.apple.com/en-us/HT213345
- https://support.apple.com/en-us/HT213346
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-48503
→ the Explorer · watch your stack · NVD