Out-of-bounds write in macOS - CVE-2022-32793
Published: July 20, 2022
Vulnerability identifier: #VU65593
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32793
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in GPU drivers. A local application can trigger an out-of-bounds write error and execute arbitrary code with root privileges.
Affected software
macOS
watchOS
Apple iOS
iPadOS
tvOS
Fedora
webkit2gtk3
watchOS
Apple iOS
iPadOS
tvOS
Fedora
webkit2gtk3
How to mitigate CVE-2022-32793
Install updates from vendor's website.
macOS - update to 12.5 21G72
Apple iOS - addressed in versions 15.6 19G71, 16.0 20A362
iPadOS - addressed in versions 15.6 19G71, 16.0 20A362
tvOS - update to 15.6 19M65
webkit2gtk3 - addressed in versions 2.36.7-1.fc35, 2.36.7-1.fc36
Apple iOS - addressed in versions 15.6 19G71, 16.0 20A362
iPadOS - addressed in versions 15.6 19G71, 16.0 20A362
tvOS - update to 15.6 19M65
webkit2gtk3 - addressed in versions 2.36.7-1.fc35, 2.36.7-1.fc36